[CVE-2026-77752] The Temporary Login Without Password WordPress plugin before

CVE-2026-77752 | CVSS: 7.2 | 严重级别: HIGH

The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing check also allows an existing account, including the attacker's own, to be promoted.

参考链接:
https://wpscan.com/vulnerability/09308b99-3142-44f0-b2e1-9f4680325d2d/

📌 数据来源: NVD 官方

⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。
滚动至顶部