Impact
The Temporary Login Without Password plugin for WordPress, in versions before 1.9.9, contains an access‑control flaw that permits any authenticated temporary user to create an Application Password. Because the plugin does not revoke the password when the temporary access expires or is disabled, the creator can maintain ongoing administrative access through REST or XML‑RPC endpoints after the administrator believes the temporary session has been who obtains a temporary login to preserve elevated privileges long after the session is revoked, effectively granting persistent unauthorized administrative control.
Affected Systems
WordPress sites that have installed the Temporary Login Without Password plugin prior to release 1.9 issue is confined to that plugin; other WordPress components are not impacted. Sites that rely on the plugin for temporary access grant to administrators or other privileged roles are at risk.
Risk and Exploitability
The vulnerability has a CVSS score of 5.5 and an EPSS score of less than 1 %, reflecting moderate severity and low exploitation likelihood. In practice, an attacker who receives a temporary login can exploit the flaw by creating an Application Password that remains active after the temporary session ends. The attack vector is remote, leveraging the site's publicly accessible REST or XML‑RPC interfaces, and the flaw invites an attacker to retain administrative rights, but it is not listed in the CISA KEV catalog.
OpenCVE Enrichment