rootpwn

medium · CVSS v3 4.3 · EPSS 0.00097

CVE-2026-92410

The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up del…

Description

The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion action, allowing attackers to delete sign-up records via a forged request handled in the session of a logged-in user with the required capability.

Scores

Severity
medium
CVSS v2
5
CVSS v3
4.3
CVSS v4
EPSS
0.00097

← All CVEs