๐Ÿ” CVE Alert

CVE-2026-92410

MEDIUM 4.3

Sign-up Sheets < 2.4.0 - Arbitrary Sign-up Deletion via CSRF

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion action, allowing attackers to delete sign-up records via a forged request handled in the session of a logged-in user with the required capability.

Vendor unknown
Product sign-up sheets
Published Sep 20, 2026
Last Updated Sep 20, 2026
Stay Ahead of the Next One

Get instant alerts for unknown sign-up sheets

Be the first to know when new medium vulnerabilities affecting unknown sign-up sheets are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Sign-up Sheets
0 < 2.4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/4c217ac6-e191-4be9-becc-47cacf2b4e25/

Credits

JunHee CHO WPScan