VYPR

Insurify

by WordPress

CVEs (2)

  • CVE-2026-86717Oct 11, 2026
    risk 0.00cvss —epss —

    The Insurify WordPress plugin through 1.0 does not have authorisation and nonce checks on one of its AJAX actions, allowing unauthenticated users to delete arbitrary WordPress options, which can take the site offline and strip every user of their role.

  • CVE-2026-85121Oct 11, 2026
    risk 0.00cvss —epss —

    The Insurify WordPress plugin through 1.0 does not have authorisation and nonce checks on one of its AJAX actions, allowing unauthenticated users to create and overwrite arbitrary WordPress options with request data, which can take the site offline and deactivate all of its…