medium · CVSS v3 4.3 · EPSS 0.00097
CVE-2026-92410
The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up del…
Description
The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion action, allowing attackers to delete sign-up records via a forged request handled in the session of a logged-in user with the required capability.
Scores
- Severity
- medium
- CVSS v2
- 5
- CVSS v3
- 4.3
- CVSS v4
- —
- EPSS
- 0.00097