Description
The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Application Password, and does not revoke one when the temporary access expires or is disabled, allowing the recipient of a temporary login to retain working access to the site over REST and XML-RPC after the administrator believes it has been withdrawn. The retained access carries whatever role was granted, which for the Temporary Login Without Password WordPress plugin before 1.9.9's main use case is Administrator.
Published: 2026-09-12
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Persistent Access
Action: Immediate Patch
AI Analysis

Impact

The Temporary Login Without Password plugin for WordPress, in versions before 1.9.9, contains an access‑control flaw that permits any authenticated temporary user to create an Application Password. Because the plugin does not revoke the password when the temporary access expires or is disabled, the creator can maintain ongoing administrative access through REST or XML‑RPC endpoints after the administrator believes the temporary session has been who obtains a temporary login to preserve elevated privileges long after the session is revoked, effectively granting persistent unauthorized administrative control.

Affected Systems

WordPress sites that have installed the Temporary Login Without Password plugin prior to release 1.9 issue is confined to that plugin; other WordPress components are not impacted. Sites that rely on the plugin for temporary access grant to administrators or other privileged roles are at risk.

Risk and Exploitability

The vulnerability has a CVSS score of 5.5 and an EPSS score of less than 1 %, reflecting moderate severity and low exploitation likelihood. In practice, an attacker who receives a temporary login can exploit the flaw by creating an Application Password that remains active after the temporary session ends. The attack vector is remote, leveraging the site's publicly accessible REST or XML‑RPC interfaces, and the flaw invites an attacker to retain administrative rights, but it is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 15, 2026 at 18:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Temporary Login Without Password plugin to version 1.9.9 or later, which revokes Application Passwords created during temporary sessions.
  • If an upgrade is not immediately possible, manually revoke any Application Passwords created by users who feature until a fix is applied.
  • Restrict or disable REST and XML‑RPC endpoints if they are not required for site functionality, or apply role‑based access controls to limit administrative actions exposed by those endpoints.

Generated by OpenCVE AI on September 15, 2026 at 18:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306

Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-306

Sat, 12 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Application Password, and does not revoke one when the temporary access expires or is disabled, allowing the recipient of a temporary login to retain working access to the site over REST and XML-RPC after the administrator believes it has been withdrawn. The retained access carries whatever role was granted, which for the Temporary Login Without Password WordPress plugin before 1.9.9's main use case is Administrator.
Title Temporary Login Without Password < 1.9.9 - Authenticated Temporary Access Revocation Bypass via Application Passwords
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-12T15:35:08.098Z

Reserved: 2026-08-21T09:51:18.720Z

Link: CVE-2026-77753

cve-icon Vulnrichment

Updated: 2026-09-12T15:24:30.943Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T06:16:25.183

Modified: 2026-09-14T21:10:17.423

Link: CVE-2026-77753

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:00:15Z

Weaknesses