Loading market data...
← Back to CVE feed

CVE-2026-92410

MEDIUM CVSS 4.3 View on NVD ↗

Description

The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion action, allowing attackers to delete sign-up records via a forged request handled in the session of a logged-in user with the required capability.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Published: Sep 20, 2026 07:16 UTC Modified: Sep 20, 2026 14:16 UTC