CVE-2026-92410: Sign-up Sheets < 2.4.0 - Arbitrary Sign-up Deletion via CSRF
Published Sep 20, 2026
·Updated
The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion action, allowing attackers to delete sign-up records via a forged request handled in the session of a logged-in user with the required capability.
Affected Software
1 affected component
WordPress Sign-up Sheets<2.4.0
Event History
Sep 20, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Which users can be leveraged to delete sign-up records?
An attacker needs a logged-in WordPress user who has the capability required to delete sign-up records. The forged request is processed in that user’s authenticated session.
2
What conditions are required for exploitation?
The attacker must cause an authorized, logged-in user to submit a forged request to the vulnerable sign-up deletion action. The issue affects Sign-up Sheets versions before 2.4.0.