Junglewise Threat Intelligence

CVE-2026-77752: Temporary Login Without Password privilege escalation in WordPress multisite

CVE-2026-77752 · Severity: high · CVSS 7.2 · Published 2026-09-12

Executive brief

The Temporary Login Without Password WordPress plugin allows site administrators on a multisite network to escalate their privileges to network super admin without proper authorization checks. An attacker with administrative rights on a single site can take over the entire network or promote their own account to super admin status, gaining unrestricted access to all sites and sensitive configuration.

Technical details

This is a privilege escalation vulnerability (CWE-269) in the plugin's temporary login creation functionality. The plugin fails to verify that a user requesting temporary login creation holds network-level super admin rights before granting those elevated privileges to the new account. The vulnerability affects authenticated users with site-level admin privileges on a multisite WordPress installation. An attacker can exploit this by creating a temporary login with network super admin rights or promoting their own existing account to super admin, achieving full network takeover. The vulnerability has been fixed in version 1.9.9; all installations running versions 1.5 through 1.9.8 are affected.

Affected products

  • BaptouTatis Temporary Login Without Password 1.5 to 1.9.8

Timeline

  • 2026-09-10: disclosed
  • 2026-09-12: patched: Fixed in version 1.9.9

References