Impact
The Sign‑up Sheets WordPress plugin releases before version 2.4.0 contain a flaw where the CSRF nonce protecting the sign‑up deletion action is not properly validated. An attacker who tricks a logged‑in user with the required capability into sending a forged request can delete arbitrary sign‑up records, compromising data integrity and potentially disrupting service.
Affected Systems
WordPress sites running the Sign‑up Sheets plugin, any version below 2.4.0. The vulnerability applies to all installations where the deletion feature is enabled and the user possesses the necessary capability.
Risk and Exploitability
The vulnerability can be exploited via a CSRF attack. The attacker must generate a request that a logged‑in user submits; no additional information disclosure or remote code execution is required. Because the EPSS score is unavailable and the vulnerability is not listed in CISA KEV, the current exploitation likelihood is unknown, but the damage potential is high. The plugin does not enforce any additional controls beyond the missing nonce check, making the attack straightforward once the target user is identified.
OpenCVE Enrichment