CVE-2026-77752
Received Received - Intake

Temporary Login Without Password WordPress Plugin Privilege Escalation

Vulnerability report for CVE-2026-77752, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-12

Last updated on: 2026-09-12

Assigner: WPScan

Description

The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing check also allows an existing account, including the attacker's own, to be promoted.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-12
Last Modified
2026-09-12
Generated
2026-09-12
AI Q&A
2026-09-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
temporary_login_without_password temporary_login_without_password From 1.5 (inc) to 1.9.9 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the WordPress plugin 'Temporary Login Without Password' versions 1.5 to 1.9.8. It allows an administrator of a single site within a multisite network to escalate privileges to network super admin rights without proper verification. The flaw also enables existing accounts to be promoted to higher privileges due to missing checks on network super admin rights.

Detection Guidance

Check the installed version of the Temporary Login Without Password plugin. If it is between 1.5 and 1.9.8, the system is vulnerable. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files in /wp-content/plugins/temporary-login-without-password/ to verify the version.

Impact Analysis

An attacker with single-site admin access could take over the entire multisite network by gaining network super admin rights. Existing accounts could also be escalated to higher privileges, potentially leading to full control of the WordPress installation and all its sites.

Compliance Impact

This vulnerability could lead to unauthorized access and control of sensitive data across all sites in a multisite network, violating compliance requirements for data protection and access control in standards like GDPR and HIPAA.

Mitigation Strategies

Update the Temporary Login Without Password plugin to version 1.9.9 or later immediately. Disable the plugin temporarily if an update is not immediately available. Review user accounts for unauthorized privilege escalations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77752. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart