Impact
The Sign‑up Sheets plugin by Fetch Designs contains a CSRF flaw (CWE‑352) that lets an attacker coerce an authenticated user to submit a forged request, potentially altering or submitting data without the user’s consent. This weakness does not provide code execution or remote exploitation, but it enables tampering with sign‑up sheet entries and other state‑changing operations, thereby compromising data integrity.
Affected Systems
All installations of the Sign‑up Sheets plugin for WordPress dated 2.3.3 or earlier are affected. The vulnerability is present in all pre‑2.3.3 releases of the plugin distributed by Fetch Designs.
Risk and Exploitability
The CVSS score is 4.3, indicating a moderate risk level, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The issue is not listed in the CISA KEV catalog. Exploitation requires a victim who is logged into the WordPress site and visits a malicious page that posts a request to the plugin’s endpoint, relying on the absence of anti‑CSRF tokens in the plugin’s requests.
OpenCVE Enrichment
EUVD