Description
The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing check also allows an existing account, including the attacker's own, to be promoted.
Published: 2026-09-12
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows a single‑site administrator on a WordPress multisite network to grant themselves or any other account network super‑admin privileges. The plugin fails to check that the requester holds network super‑admin rights before assigning such authority, resulting in full control over the entire network’s administrative functions and compromising all sites and data. The flaw complete privilege escalation, directly missing check permits an existing account—including the attacker's own—to be promoted to network super‑admin, expanding the potential impact.

Affected Systems

WordPress sites running the Temporary Login Without Password plugin version 1.5 up to (but not including) 1.9.9 on a multisite network are affected. The plugin is the only component involved; no other WordPress products are directly impacted.

Risk and Exploitability

The flaw is exploitable through normal site administrator actions; an attacker only needs to use the temporary login feature from the site admin panel, a well‑known interface. Because the flaw allows immediate elevation the vulnerability rate is high. The CVSS score of 7.2 reflects a high severity rating. The EPSS score indicates a probability of exploitation of less than 1% in the wild, and the vulnerability is not listed in CISA KEV. The likely attack vector is the web interface used by a site‑level administrative account. Once exploited, the attacker can assume any administrative role across the multisite network.

Generated by OpenCVE AI on September 15, 2026 at 18:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Temporary Login Without Password plugin to version 1.9.9 or newer.
  • If upgrading is not possible, disable or uninstall the plugin to eliminate the attack surface.
  • Ensure that any temporary login or role‑assignment feature verifies the requester's network super‑admin status before granting such rights.

Generated by OpenCVE AI on September 15, 2026 at 18:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-264
CWE-285

Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-264
CWE-285

Sat, 12 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing check also allows an existing account, including the attacker's own, to be promoted.
Title Temporary Login Without Password 1.5 - 1.9.8 - Multisite Subsite Admin+ Network Super Admin Privilege Escalation
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-12T15:35:23.105Z

Reserved: 2026-08-21T09:51:02.304Z

Link: CVE-2026-77752

cve-icon Vulnrichment

Updated: 2026-09-12T15:24:50.607Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T06:16:25.070

Modified: 2026-09-14T21:10:17.423

Link: CVE-2026-77752

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:00:15Z

Weaknesses
  • CWE-269

    Improper Privilege Management