Skip to main content
Vulnerability Database/CVE-2026-92410

CVE-2026-92410: Sign-up Sheets WordPress CSRF Vulnerability

CVE-2026-92410 is a cross-site request forgery flaw in Sign-up Sheets WordPress plugin that enables attackers to delete sign-up records through forged requests. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-92410 Overview

The Sign-up Sheets WordPress plugin before version 2.4.0 contains a Cross-Site Request Forgery (CSRF) vulnerability [CWE-352]. The plugin fails to properly validate the CSRF nonce protecting its sign-up deletion action. Attackers can forge a request that deletes sign-up records when a logged-in user with the required capability visits an attacker-controlled page. Exploitation requires user interaction from a privileged session but does not require the attacker to authenticate.

Critical Impact

Successful exploitation allows unauthorized deletion of sign-up records through a forged request executed in the browser of a logged-in privileged user, resulting in limited data integrity loss.

Affected Products

  • Sign-up Sheets WordPress plugin versions prior to 2.4.0
  • WordPress sites with the plugin installed and active
  • Administrative sessions holding the required plugin capability

Discovery Timeline

  • 2026-09-20 - CVE-2026-92410 published to NVD
  • 2026-09-21 - Last updated in NVD database

Technical Details for CVE-2026-92410

Vulnerability Analysis

The vulnerability resides in the sign-up deletion handler of the Sign-up Sheets plugin. The handler is intended to be protected by a WordPress nonce, a token that binds a request to a specific user session and action. Improper validation of this nonce means the deletion endpoint accepts requests that lack a valid, session-bound token.

An attacker crafts an HTML page or link that issues the deletion request to the target site. When an authenticated user with the required capability loads the attacker's content, the browser submits the request with the victim's authentication cookies. The plugin then processes the deletion as if the victim initiated it. Impact is limited to the integrity of stored sign-up records; confidentiality and availability of the wider site are not directly affected.

Root Cause

The root cause is missing or incorrect nonce verification in the deletion action. WordPress provides check_admin_referer() and wp_verify_nonce() for this purpose, and the vulnerable code path either omits the check or applies it in a manner that does not reject unauthenticated cross-origin submissions. This is a classic instance of CWE-352: Cross-Site Request Forgery.

Attack Vector

Exploitation is network-based and requires user interaction. The attacker hosts a page containing an auto-submitting form or image tag that targets the plugin's deletion endpoint on the vulnerable WordPress site. A logged-in user with sign-up management capability must visit that page for the forged request to succeed. No credentials or prior access to the target site are required by the attacker.

Technical details are documented in the WPScan Vulnerability Report.

Detection Methods for CVE-2026-92410

Indicators of Compromise

  • Unexpected deletion of sign-up records without corresponding admin activity in audit logs
  • HTTP POST or GET requests to the plugin's deletion endpoint with Referer headers pointing to external domains
  • Access log entries showing deletion actions immediately following navigation from untrusted origins

Detection Strategies

  • Review WordPress database logs for DELETE operations against Sign-up Sheets tables that lack corresponding administrator UI activity
  • Correlate web server access logs with admin session activity to identify deletion requests originating from cross-origin referrers
  • Monitor for the plugin's deletion action parameters appearing in requests without the expected nonce query string

Monitoring Recommendations

  • Enable a WordPress audit logging plugin to capture create, update, and delete events on Sign-up Sheets records with the acting user and source IP
  • Alert on any HTTP request to wp-admin/admin.php or admin-post.php invoking the plugin's delete action with an off-site Referer
  • Track the plugin version installed across managed WordPress instances and flag hosts running versions below 2.4.0

How to Mitigate CVE-2026-92410

Immediate Actions Required

  • Update the Sign-up Sheets WordPress plugin to version 2.4.0 or later on all affected sites
  • Instruct privileged users to log out of WordPress before browsing unrelated sites until patches are applied
  • Audit existing sign-up records and restore any that were deleted without authorization from backups

Patch Information

The vendor released version 2.4.0 of the Sign-up Sheets plugin, which addresses the improper CSRF nonce validation in the sign-up deletion action. Refer to the WPScan Vulnerability Report for the fixed version reference.

Workarounds

  • Deactivate the Sign-up Sheets plugin until it can be updated to 2.4.0 or later
  • Restrict the plugin's management capability to a minimal set of accounts to reduce the exploitable user population
  • Deploy a web application firewall rule that requires a valid same-origin Referer on the plugin's deletion endpoint
bash
# Example WP-CLI command to update the plugin site-wide
wp plugin update signup-sheets --version=2.4.0

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.