CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-86717: Insurify 0 through 1.0

CVE-2026-86717. CVSS 3.1 base score 9.1 (CRITICAL, Source advisory).

Affected technology

Insurify · 0 through 1.0
Vendor not specified by the source

Description’s affected range: through 1.0 does not have authorisation and nonce checks on one of its AJAX actions

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

Unauthenticated users can delete arbitrary WordPress options, which can take the site offline and strip every user of their role. Source advisory’s CVSS 3.1 assessment (base score 9.1/10) rates confidentiality impact as none; integrity and availability impact as high.

Published

CWE
CWE-862
CCR priority
36.4 /100 (P4)
CVSS 3.1
9.1 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H · Source advisory
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-86717.html