PatchSiren

Sign-up Sheets CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Sign-up Sheets CVE published 2026-09-20

CVE-2026-92410

The Sign-up Sheets WordPress plugin before 2.4.0 has a CSRF nonce flaw that allows attackers to delete sign-up records via forged requests in logged-in user sessions with required capabilities. This could disrupt user registration and management functionality. Verify plugin version and update to 2.4.0 or later to prevent exploitation. Restrict access to sign-up deletion functionality to only those who req [truncated]