PatchSiren cyber security CVE debrief
CVE-2026-92410 Sign-up Sheets CVE debrief
The Sign-up Sheets WordPress plugin before 2.4.0 has a CSRF nonce flaw that allows attackers to delete sign-up records via forged requests in logged-in user sessions with required capabilities. This could disrupt user registration and management functionality. Verify plugin version and update to 2.4.0 or later to prevent exploitation. Restrict access to sign-up deletion functionality to only those who require it. Monitor for suspicious activity related to sign-up deletion. Assess exposure and verify plugin version; restrict sign-up deletion access.
- Vendor
- Sign-up Sheets
- Product
- Sign-up Sheets WordPress plugin
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-20
- Original CVE updated
- 2026-09-20
- Advisory published
- 2026-09-20
- Advisory updated
- 2026-09-20
Who should care
WordPress administrators and users with the required capability to delete sign-up records should assess their exposure and verify the plugin version. They should also restrict access to sign-up deletion functionality to only those who require it and monitor for suspicious activity related to sign-up deletion.
Why it matters
The Sign-up Sheets WordPress plugin before 2.4.0 has a CSRF nonce flaw that allows attackers to delete sign-up records. WordPress administrators and users with the required capability should assess their exposure and verify the plugin version.
- An attacker could delete sign-up records, potentially disrupting user registration and management functionality.
- Verify plugin version and update to 2.4.0 or later to prevent exploitation.
- Restrict access to sign-up deletion functionality to only those who require it.
Technical summary
The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion action, allowing attackers to delete sign-up records via a forged request handled in the session of a logged-in user with the required capability. This could allow an attacker to disrupt user registration and management functionality. Verify plugin version and update to 2.4.0 or later to prevent exploitation. Restrict access to sign-up deletion functionality to only those who require it. Assess exposure and verify plugin version.
Defensive priority
Assess exposure and verify plugin version; restrict sign-up deletion access
Recommended defensive actions
- Verify the version of the Sign-up Sheets WordPress plugin and update to 2.4.0 or later if necessary
- Restrict access to sign-up deletion functionality to only those who require it
- Monitor for suspicious activity related to sign-up deletion
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. Further verification is required to determine the affected versions and potential impact. The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion action. The CVE Program record and NVD detail page offer source-provided CVE metadata and vulnerability assessment. Verify plugin version and assess exposure.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-92410 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-92410
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-92410 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92410
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/4c217ac6-e191-4be9-becc-47cacf2b4e25/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.