Mmastodon TechnologyCybersecurity first seen 9 h ago, last 9 h ago, peak #8
Critical flaw in Insurify WordPress plugin allows site takeover
Original: CVE-2026-86717 (CRITICAL) targets Insurify WP plugin ≤1.0. Missing auth & nonce checks in AJAX lets unauth users delete
A critical vulnerability, CVE-2026-86717, has been disclosed in the Insurify WordPress plugin, versions 1.0 and below. Missing authentication and nonce checks in its AJAX functions let unauthenticated attackers delete WordPress options, potentially taking sites offline or wiping user roles. Security researchers urge users to disable or restrict the plugin until a fix is available.
Why now: A newly published critical CVE with a simple exploitation path puts any site running the plugin at immediate risk.
CVE-2026-86717Insurify WordPress pluginWordPress
Evidence
- CVE-2026-86717 (CRITICAL) targets Insurify WP plugin ≤1.0. Missing auth & nonce checks in AJAX lets unauth users delete WordPress options — site can be taken offline, user roles wiped. Disable or restrict plugin. https:// radar.offseq.com/threat/cve-20… · offseq@infosec.exchange · 1
API: https://socialmediatrends-api.osmike.com/v1/trends/1856015