Sign-up Sheets <= 2.3.2 - Unauthenticated PHP Object Injection
high
The Sign-up Sheets plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3.2 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present v...
- CVSS:
- 8.1
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.3
- Disclosed:
- Sep 23, 2025
CVE-2025-49393 on NVD →
Sign-up Sheets <= 2.3.3 - Cross-Site Request Forgery
medium
The Sign-up Sheets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site admini...
- CVSS:
- 4.3
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.3.1
- Disclosed:
- Aug 20, 2025
CVE-2025-49391 on NVD →
Sign-up Sheets [sign-up-sheets] < 2.3.3.1
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Fetch Designs Sign-up Sheets allows Cross Site Request Forgery. This issue affects Sign-up Sheets: from n/a through 2.3.3.
- Affected:
- up to 2.3.3.1
- Fixed in:
- 2.3.3.1
- Disclosed:
- Aug 20, 2025
CVE-2025-49391 on NVD →
Sign-up Sheets <= 2.3.0.1 - Unauthenticated Arbitrary Shortcode Execution
medium
The The Sign-up Sheets plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.3.0.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attack...
- CVSS:
- 6.5
- Affected:
- up to 2.3.0.1
- Fixed in:
- 2.3.1
- Disclosed:
- Apr 15, 2025
CVE-2025-26996 on NVD →
Sign-up Sheets [sign-up-sheets] < 2.3.1
unknown
[en] Improper Control of Generation of Code ('Code Injection') vulnerability in Fetch Designs Sign-up Sheets allows Code Injection. This issue affects Sign-up Sheets: from n/a through 2.3.0.1.
- Affected:
- up to 2.3.1
- Fixed in:
- 2.3.1
- Disclosed:
- Apr 15, 2025
CVE-2025-26996 on NVD →
Sign-up Sheets [sign-up-sheets] < 2.2.13
unknown
[en] Missing Authorization vulnerability in Fetch Designs Sign-up Sheets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sign-up Sheets: from n/a through 2.2.12.
- Affected:
- up to 2.2.13
- Fixed in:
- 2.2.13
- Disclosed:
- Nov 1, 2024
CVE-2024-39654 on NVD →
Sign-up Sheets [sign-up-sheets] < 2.2.13
unknown
[en] The Sign-up Sheets WordPress plugin before 2.2.13 does not escape some generated URLs, as well as the $_SERVER['REQUEST_URI'] parameter before outputting them back in attributes, which could lead to Reflected Cross-Site Scripting.
- Affected:
- up to 2.2.13
- Fixed in:
- 2.2.13
- Disclosed:
- Sep 4, 2024
CVE-2024-6020 on NVD →
Sign-up Sheets <= 2.2.12 - Reflected Cross-Site Scripting
medium
The Sign-up Sheets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['REQUEST_URI'] without appropriate escaping on the URL in all versions up to, and including, 2.2.12. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execu...
- CVSS:
- 6.1
- Affected:
- up to 2.2.12
- Fixed in:
- 2.2.13
- Disclosed:
- Aug 13, 2024
CVE-2024-6020 on NVD →
Sign-up Sheets <= 2.2.12 - Missing Authorization
medium
The Sign-up Sheets plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cleanArray() function in versions up to, and including, 2.2.12. This makes it possible for unauthenticated attackers to clean data.
- CVSS:
- 5.3
- Affected:
- up to 2.2.12
- Fixed in:
- 2.2.13
- Disclosed:
- Aug 1, 2024
CVE-2024-39654 on NVD →
Sign-up Sheets [sign-up-sheets] < 2.2.12
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Fetch Designs Sign-up Sheets.This issue affects Sign-up Sheets: from n/a through 2.2.11.1.
- Affected:
- up to 2.2.12
- Fixed in:
- 2.2.12
- Disclosed:
- Apr 12, 2024
CVE-2024-31303 on NVD →
Sign-up Sheets <= 2.2.11.1 - Cross-Site Request Forgery
medium
The Sign-up Sheets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.11.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can...
- CVSS:
- 4.3
- Affected:
- up to 2.2.11.1
- Fixed in:
- 2.2.12
- Disclosed:
- Apr 5, 2024
CVE-2024-31303 on NVD →
Sign-up Sheets [sign-up-sheets] < 2.2.9
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Fetch Designs Sign-up Sheets plugin <= 2.2.8 versions.
- Affected:
- up to 2.2.9
- Fixed in:
- 2.2.9
- Disclosed:
- Oct 3, 2023
CVE-2023-39165 on NVD →
Sign-up Sheets <= 2.2.8 - Cross-Site Request Forgery
medium
The Sign-up Sheets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.8. This is due to missing nonce validation on the maybeProcessReset() and maybeProcessSave() functions. This makes it possible for unauthenticated attackers to save and reset the plugin's settings v...
- CVSS:
- 4.3
- Affected:
- up to 2.2.8
- Fixed in:
- 2.2.9
- Disclosed:
- Aug 7, 2023
CVE-2023-39165 on NVD →
Sign-up Sheets [sign-up-sheets] < 1.0.14
unknown
[en] The Sign-up Sheets WordPress plugin before 1.0.14 does not not sanitise or validate the Sheet title when generating the CSV to export, which could lead to a CSV injection issue
- Affected:
- up to 1.0.14
- Fixed in:
- 1.0.14
- Disclosed:
- Jul 12, 2021
CVE-2021-24441 on NVD →
Sign-up Sheets [sign-up-sheets] < 1.0.14
unknown
[en] The Sign-up Sheets WordPress plugin before 1.0.14 did not sanitise or escape some of its fields when creating a new sheet, allowing high privilege users to add JavaScript in them, leading to a Stored Cross-Site Scripting issue. The payloads will be triggered when viewing the 'All Sheets' page in the admin dashboar...
- Affected:
- up to 1.0.14
- Fixed in:
- 1.0.14
- Disclosed:
- Jul 12, 2021
CVE-2021-24440 on NVD →
Sign-up Sheets <= 1.0.13 - Authenticated CSV Injection
high
The Sign-up Sheets WordPress plugin before 1.0.14 does not not sanitise or validate the Sheet title when generating the CSV to export, which could lead to a CSV injection issue
- CVSS:
- 8
- Affected:
- up to 1.0.14
- Fixed in:
- 1.0.14
- Disclosed:
- Jun 21, 2021
CVE-2021-24441 on NVD →
Sign-up Sheets <= 1.0.13 - Stored Cross-Site Scripting
medium
The Sign-up Sheets WordPress plugin before 1.0.14 did not sanitise or escape some of its fields when creating a new sheet, allowing high privilege users to add JavaScript in them, leading to a Stored Cross-Site Scripting issue. The payloads will be triggered when viewing the 'All Sheets' page in the admin dashboard
- CVSS:
- 4.8
- Affected:
- up to 1.0.14
- Fixed in:
- 1.0.14
- Disclosed:
- Jun 21, 2021
CVE-2021-24440 on NVD →
Sign-up Sheets [sign-up-sheets] < 2.3.3
unknown
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.3
CVE-2025-49393 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database