CVE-2026-92410 PUBLISHED

Sign-up Sheets < 2.4.0 - Arbitrary Sign-up Deletion via CSRF

Assigner: WPScan
Reserved: 16.09.2026 Published: 20.09.2026 Updated: 20.09.2026

The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion action, allowing attackers to delete sign-up records via a forged request handled in the session of a logged-in user with the required capability.

Product Status

Vendor Unknown
Product Sign-up Sheets
Versions Default: unaffected
  • affected from 0 to 2.4.0 (excl.)

Credits

  • JunHee CHO finder
  • WPScan coordinator

References

Problem Types

  • CWE-352 Cross-Site Request Forgery (CSRF) CWE