CVE-2026-77753
Received Received - Intake

Temporary Login Without Password WordPress plugin privilege escalation

Vulnerability report for CVE-2026-77753, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-12

Last updated on: 2026-09-12

Assigner: WPScan

Description

The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Application Password, and does not revoke one when the temporary access expires or is disabled, allowing the recipient of a temporary login to retain working access to the site over REST and XML-RPC after the administrator believes it has been withdrawn. The retained access carries whatever role was granted, which for the Temporary Login Without Password WordPress plugin before 1.9.9's main use case is Administrator.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-12
Last Modified
2026-09-12
Generated
2026-09-12
AI Q&A
2026-09-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
temporary_login_without_password temporary_login_without_password to 1.9.9 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Temporary Login Without Password WordPress plugin before version 1.9.9 has a flaw where temporary user access is not properly revoked. When a temporary login is created, the user can generate an Application Password that remains active even after the temporary access expires or is disabled. This allows the user to retain access to the site via REST and XML-RPC interfaces, bypassing the intended access revocation.

Detection Guidance

Check if your WordPress site is running the Temporary Login Without Password plugin version prior to 1.9.9. Use commands like 'wp plugin list' in WP-CLI or inspect the plugin files for version details. Look for unauthorized Application Passwords created by temporary users in the WordPress REST or XML-RPC interfaces.

Impact Analysis

If you use this plugin, an attacker with temporary admin access could create a persistent backdoor. Even after you disable their temporary login, they could still access your site using the Application Password, potentially leading to data theft, unauthorized changes, or further compromise of your WordPress installation.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR's data protection requirements and HIPAA's security rules. If sensitive user data is exposed due to retained access, organizations may face regulatory penalties, legal consequences, and reputational damage.

Mitigation Strategies

Update the Temporary Login Without Password plugin to version 1.9.9 or later immediately. Review and revoke any Application Passwords created by temporary users. Disable REST and XML-RPC access if not required, or monitor them closely for unauthorized activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77753. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart