CVE-2026-77752 PUBLISHED

Temporary Login Without Password 1.5 - 1.9.8 - Multisite Subsite Admin+ Network Super Admin Privilege Escalation

Assigner: WPScan
Reserved: 21.08.2026 Published: 12.09.2026 Updated: 12.09.2026

The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing check also allows an existing account, including the attacker's own, to be promoted.

Product Status

Vendor Unknown
Product Temporary Login Without Password
Versions Default: unaffected
  • affected from 1.5 to 1.9.9 (excl.)

Credits

  • BaptouTatis finder
  • WPScan coordinator

References

Problem Types

  • CWE-269 Improper Privilege Management CWE