HIGH
CVE-2026-77752
CVSS
7.2
Description
The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing check also allows an existing account, including the attacker's own, to be promoted.
Weakness (CWE)
CWE-269
Improper Privilege Management
EPSS Score
0.32%
Probability of exploitation in next 30 days
24.8th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.