The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion action, allowing attackers to delete sign-up records via a forged request handled in the session of a logged-in user with the required capability.
CVE-2026-92410
NONE
EPSS 0.10%
Updated Sep 20, 2026
Unknown
unknown:sign-up sheets
CVE Details
CVE ID
CVE-2026-92410
Published Date
Sep 20, 2026
Vendor
Unknown
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.10%
Likelihood of exploitation in next 30 days
Percentile:
0.8th percentile (higher than 0.8% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory