CVE-2026-92410
Received Received - Intake

CSRF in Sign-up Sheets WordPress Plugin

Vulnerability report for CVE-2026-92410, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-20

Last updated on: 2026-09-20

Assigner: WPScan

Description

The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion action, allowing attackers to delete sign-up records via a forged request handled in the session of a logged-in user with the required capability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-20
Last Modified
2026-09-20
Generated
2026-09-20
AI Q&A
2026-09-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wp_sign_up_sheets sign_up_sheets to 2.4.0 (exc)
wpsecure sign-up_sheets to 2.4.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Cross-Site Request Forgery (CSRF) issue in the Sign-up Sheets WordPress plugin versions before 2.4.0. The plugin does not properly validate the CSRF nonce required for deleting sign-up records, allowing attackers to delete these records by tricking a logged-in user with the necessary permissions into submitting a forged request.

Detection Guidance

Check the installed version of the Sign-up Sheets WordPress plugin. If it is below 2.4.0, the system is vulnerable. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files directly.

Impact Analysis

If you use the Sign-up Sheets plugin before version 2.4.0, an attacker could delete sign-up records without your knowledge. This could disrupt your event or sign-up management, leading to data loss or operational issues if the deleted records are critical.

Mitigation Strategies

Update the Sign-up Sheets plugin to version 2.4.0 or later immediately. If updating is not possible, consider disabling the plugin until an update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92410. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart