The Insurify WordPress plugin through 1.0 has a critical vulnerability allowing unauthenticated users to delete arbitrary WordPress options. This could potentially take the site offline and strip every user of their role. Site administrators should assess exposure and verify plugin versions immediately. The vulnerability exists due to a lack of authorization and nonce checks on one of its AJAX actions. Th [truncated]
The Insurify WordPress plugin through 1.0 has a vulnerability allowing unauthenticated users to create and overwrite arbitrary WordPress options, potentially taking the site offline and deactivating the Insurify WordPress plugin. This issue arises from a lack of authorization and nonce checks on an AJAX action, which can be exploited by unauthenticated users to modify site options. Defenders managing Word [truncated]