Impact
The Temporary Login Without Password plugin before version 1.9.9 allows an authenticated temporary user to create an Application Password. The plugin fails to revoke this password when the temporary access expires or is disabled, so the person who receives the temporary login can maintain administrative access via REST and XML‑RPC endpoints. Because the retained access carries the role granted at the time of the temporary login—typically administrator—the flaw enables long‑term unauthorized administrative control. The CVSS score is 5.5 and the EPSS is <1%, indicating moderate severity and low exploitation probability, yet the impact remains significant due to persistent administrative rights.
Affected Systems
WordPress sites that use the Temporary Login Without Password plugin in any pre‑1.9.9 release. The vulnerability is limited to that plugin.
Risk and Exploitability
An attacker who has obtained a temporary login can exploit the vulnerability by creating an application password that persists after the temporary access is revoked. The attack vector is remote, using the site’s REST or XML‑RPC interfaces. Although the CVSS score is 5.5 and the EPSS is <1%, the ability to retain permanent administrative privileges after revocation creates a serious security risk. This flaw is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment