Description
The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing check also allows an existing account, including the attacker's own, to be promoted.
Published: 2026-09-12
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows a single‑site administrator on a WordPress multisite network to grant themselves or any other account network super‑admin privileges. The plugin fails to check that the requester holds network super‑admin rights before assigning such authority, resulting in full control over the entire network’s administrative functions and compromising all sites and data. The flaw is an authorization bypass that produces a complete privilege escalation, directly affecting confidentiality, integrity, and availability of the missing check permits an existing account—including the attacker's own—to be promoted to network super‑admin, expanding the potential impact.

Affected Systems

WordPress sites running the Temporary Login Without Password plugin version 1.5 up to (but not including) 1.9.9 on a multisite network are affected. The plugin is the only component involved; no other WordPress products are directly impacted.

Risk and Exploitability

The flaw is exploitable through normal site‑admin actions; an attacker only needs to use the temporary login feature from the site admin panel, a well‑known interface. Because the flaw allows immediate elevation to network super‑admin, the impact is severe. The EPSS score of < 1% indicates a low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA KEV. The likely attack vector is the web interface used by a ownership of a site‑level administrative account. Once exploited, the attacker can assume any administrative role across the multisite network.

Generated by OpenCVE AI on September 12, 2026 at 18:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Temporary Login Without Password plugin to version 1.9.9 or later before it is available.
  • If upgrading is not possible, disable or uninstall the plugin to eliminate the attack surface.
  • Ensure that any temporary login or role‑assignment feature verifies the requester's network super‑admin status before granting such rights.

Generated by OpenCVE AI on September 12, 2026 at 18:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-264
CWE-285

Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-264
CWE-285

Sat, 12 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing check also allows an existing account, including the attacker's own, to be promoted.
Title Temporary Login Without Password 1.5 - 1.9.8 - Multisite Subsite Admin+ Network Super Admin Privilege Escalation
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-12T15:35:23.105Z

Reserved: 2026-08-21T09:51:02.304Z

Link: CVE-2026-77752

cve-icon Vulnrichment

Updated: 2026-09-12T15:24:50.607Z

cve-icon NVD

Status : Received

Published: 2026-09-12T06:16:25.070

Modified: 2026-09-12T16:16:39.080

Link: CVE-2026-77752

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-12T18:30:15Z

Weaknesses
  • CWE-269

    Improper Privilege Management