Executive brief
The Temporary Login Without Password WordPress plugin allows site administrators on a multisite network to escalate their privileges to network super admin without proper authorization checks. An attacker with administrative rights on a single site can take over the entire network or promote their own account to super admin status, gaining unrestricted access to all sites and sensitive configuration.
Technical details
This is a privilege escalation vulnerability (CWE-269) in the plugin's temporary login creation functionality. The plugin fails to verify that a user requesting temporary login creation holds network-level super admin rights before granting those elevated privileges to the new account. The vulnerability affects authenticated users with site-level admin privileges on a multisite WordPress installation. An attacker can exploit this by creating a temporary login with network super admin rights or promoting their own existing account to super admin, achieving full network takeover. The vulnerability has been fixed in version 1.9.9; all installations running versions 1.5 through 1.9.8 are affected.
Affected products
- BaptouTatis Temporary Login Without Password 1.5 to 1.9.8
Timeline
- 2026-09-10: disclosed
- 2026-09-12: patched: Fixed in version 1.9.9