Impact
The vulnerability allows a single‑site administrator on a WordPress multisite network to grant themselves or any other account network super‑admin privileges. The plugin fails to check that the requester holds network super‑admin rights before assigning such authority, resulting in full control over the entire network’s administrative functions and compromising all sites and data. The flaw is an authorization bypass that produces a complete privilege escalation, directly affecting confidentiality, integrity, and availability of the missing check permits an existing account—including the attacker's own—to be promoted to network super‑admin, expanding the potential impact.
Affected Systems
WordPress sites running the Temporary Login Without Password plugin version 1.5 up to (but not including) 1.9.9 on a multisite network are affected. The plugin is the only component involved; no other WordPress products are directly impacted.
Risk and Exploitability
The flaw is exploitable through normal site‑admin actions; an attacker only needs to use the temporary login feature from the site admin panel, a well‑known interface. Because the flaw allows immediate elevation to network super‑admin, the impact is severe. The EPSS score of < 1% indicates a low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA KEV. The likely attack vector is the web interface used by a ownership of a site‑level administrative account. Once exploited, the attacker can assume any administrative role across the multisite network.
OpenCVE Enrichment