Description
The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Application Password, and does not revoke one when the temporary access expires or is disabled, allowing the recipient of a temporary login to retain working access to the site over REST and XML-RPC after the administrator believes it has been withdrawn. The retained access carries whatever role was granted, which for the Temporary Login Without Password WordPress plugin before 1.9.9's main use case is Administrator.
Published: 2026-09-12
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Persistent Access
Action: Immediate Patch
AI Analysis

Impact

The Temporary Login Without Password plugin before version 1.9.9 allows an authenticated temporary user to create an Application Password. The plugin fails to revoke this password when the temporary access expires or is disabled, so the person who receives the temporary login can maintain administrative access via REST and XML‑RPC endpoints. Because the retained access carries the role granted at the time of the temporary login—typically administrator—the flaw enables long‑term unauthorized administrative control. The CVSS score is 5.5 and the EPSS is <1%, indicating moderate severity and low exploitation probability, yet the impact remains significant due to persistent administrative rights.

Affected Systems

WordPress sites that use the Temporary Login Without Password plugin in any pre‑1.9.9 release. The vulnerability is limited to that plugin.

Risk and Exploitability

An attacker who has obtained a temporary login can exploit the vulnerability by creating an application password that persists after the temporary access is revoked. The attack vector is remote, using the site’s REST or XML‑RPC interfaces. Although the CVSS score is 5.5 and the EPSS is <1%, the ability to retain permanent administrative privileges after revocation creates a serious security risk. This flaw is not currently listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 12, 2026 at 17:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Temporary Login Without Password plugin to version 1.9.9 or later.
  • Disable temporary login functionality or revoke all created Application Passwords manually after temporary access is removed.
  • Monitor the site for unrevoked Application Passwords and restrict or disable REST and XML‑RPC endpoints if they are not required.

Generated by OpenCVE AI on September 12, 2026 at 17:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306

Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-306

Sat, 12 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Application Password, and does not revoke one when the temporary access expires or is disabled, allowing the recipient of a temporary login to retain working access to the site over REST and XML-RPC after the administrator believes it has been withdrawn. The retained access carries whatever role was granted, which for the Temporary Login Without Password WordPress plugin before 1.9.9's main use case is Administrator.
Title Temporary Login Without Password < 1.9.9 - Authenticated Temporary Access Revocation Bypass via Application Passwords
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-12T15:35:08.098Z

Reserved: 2026-08-21T09:51:18.720Z

Link: CVE-2026-77753

cve-icon Vulnrichment

Updated: 2026-09-12T15:24:30.943Z

cve-icon NVD

Status : Received

Published: 2026-09-12T06:16:25.183

Modified: 2026-09-12T16:16:39.220

Link: CVE-2026-77753

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-12T17:45:17Z

Weaknesses