CVE-2026-77752

The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing check also allows an existing account, including the attacker's own, to be promoted.

Scoring

Severity
HIGH
CVSS base score
7.2
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS probability
0.32%
Published
2026-09-12
Last modified
2026-09-12

Affected products

Markdown version · Browse all CVEs