ZeroHour

CVE-2026-77752

large

Missing Super-Admin Check in WordPress Temporary Login Without Password Plugin

CVSS 3.1
7.2 high
EPSS
Published
()
Modified
AI analysis

The Temporary Login Without Password WordPress plugin before 1.9.9 fails to verify that the user requesting a temporary login holds network super admin rights before granting the new temporary account those rights. On a multisite network, an administrator of a single site can trigger this through the plugin's normal temporary-login creation flow and receive a temporary account with super admin privileges, escalating from control of one site to takeover of the entire network. The same missing check also allows an existing account, including the attacker's own, to be promoted. Any multisite installation running a version before 1.9.9 where site administrators can use the plugin is affected. No public proof of concept is known and the flaw is not on CISA's KEV list, so exploitation is currently none known.

What to do: Upgrade to Temporary Login Without Password 1.9.9 or later immediately. On multisite networks, network-deactivate the plugin or otherwise prevent single-site administrators from creating temporary logins, then audit the super admin user list and any existing temporary logins for unexpected accounts or promotions. Review activity logs for temporary-login creations initiated by non-super-admin users and revoke any sessions they created.

Affected
StoreApps Temporary Login Without Password (WordPress plugin)< 1.9.9
Estimated exposure
large≈300,000–400,000 sites run the plugin overall (WordPress.org active-install counts), with the exploitable multisite subset likely in the tens of thousands of… — The plugin is widely deployed (hundreds of thousands of active installs per the WordPress.org plugin directory), but only the minority of WordPress installations that run multisite are exploitable, since single-site administrators already…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing check also allows an existing account, including the attacker's own, to be promoted.

Ecosystems
WordPress
Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.