CVE-2026-77752
largeMissing Super-Admin Check in WordPress Temporary Login Without Password Plugin
The Temporary Login Without Password WordPress plugin before 1.9.9 fails to verify that the user requesting a temporary login holds network super admin rights before granting the new temporary account those rights. On a multisite network, an administrator of a single site can trigger this through the plugin's normal temporary-login creation flow and receive a temporary account with super admin privileges, escalating from control of one site to takeover of the entire network. The same missing check also allows an existing account, including the attacker's own, to be promoted. Any multisite installation running a version before 1.9.9 where site administrators can use the plugin is affected. No public proof of concept is known and the flaw is not on CISA's KEV list, so exploitation is currently none known.
What to do: Upgrade to Temporary Login Without Password 1.9.9 or later immediately. On multisite networks, network-deactivate the plugin or otherwise prevent single-site administrators from creating temporary logins, then audit the super admin user list and any existing temporary logins for unexpected accounts or promotions. Review activity logs for temporary-login creations initiated by non-super-admin users and revoke any sessions they created.
| StoreApps Temporary Login Without Password (WordPress plugin) | < 1.9.9 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing check also allows an existing account, including the attacker's own, to be promoted.
- Ecosystems
- WordPress
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.