{"id":"CVE-2026-77752","title":"The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a s…","summary":"The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a s…","severity":"high","cvss":7.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-269"],"product":"Temporary Login Without Password","affected":["temporary_login_without_password >= 1.5 < 1.9.9"],"published":"2026-09-12","updated":"2026-09-14","sourceUpdated":"2026-09-14T21:10:17.423","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-77752","references":[{"url":"https://wpscan.com/vulnerability/09308b99-3142-44f0-b2e1-9f4680325d2d/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"epss":0.00316,"epssPercentile":0.24726,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-12T15:25:59.746554Z"},"ingestedAt":"2026-09-14T15:23:07.478Z","slug":"CVE-2026-77752","body":"## Overview\n\nThe Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing check also allows an existing account, including the attacker's own, to be promoted.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":39.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}