CVE-2026-77752: Temporary Login Without Password 1.5 - 1.9.8 - Multisite Subsite Admin+ Network Super Admin Privilege Escalation
The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing check also allows an existing account, including the attacker's own, to be promoted.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An administrator of a single site within a WordPress multisite network can exploit it. The vulnerable plugin fails to confirm that the requester is a network super admin before assigning network super admin privileges.
Are non-multisite WordPress installations affected?
The described privilege escalation requires a WordPress multisite network and a user with administrator access to one of its subsites. The provided information does not indicate an impact on non-multisite installations.
What access does an attacker gain?
An attacker can grant network super admin rights to a newly created temporary-login account or promote an existing account, including their own. This allows takeover of the entire multisite network.
What version should be deployed to address the issue?
Upgrade Temporary Login Without Password to version 1.9.9 or later. Versions before 1.9.9 are affected according to the provided information.