CVE-2026-77752: Temporary Login Without Password 1.5 - 1.9.8 - Multisite Subsite Admin+ Network Super Admin Privilege Escalation

Published Sep 12, 2026
·
Updated

The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing check also allows an existing account, including the attacker's own, to be promoted.

Affected Software

1 affected component
WordPress Temporary Login Without Password<1.9.9

Event History

Sep 12, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An administrator of a single site within a WordPress multisite network can exploit it. The vulnerable plugin fails to confirm that the requester is a network super admin before assigning network super admin privileges.

2

Are non-multisite WordPress installations affected?

The described privilege escalation requires a WordPress multisite network and a user with administrator access to one of its subsites. The provided information does not indicate an impact on non-multisite installations.

3

What access does an attacker gain?

An attacker can grant network super admin rights to a newly created temporary-login account or promote an existing account, including their own. This allows takeover of the entire multisite network.

4

What version should be deployed to address the issue?

Upgrade Temporary Login Without Password to version 1.9.9 or later. Versions before 1.9.9 are affected according to the provided information.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203