VYPR

Temporary Login Without Password

by WordPress

CVEs (3)

  • CVE-2026-77752HigSep 12, 2026
    risk 0.47cvss 7.2epss 0.00

    The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take…

  • CVE-2026-77753MedSep 12, 2026
    risk 0.36cvss 5.5epss 0.00

    The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Application Password, and does not revoke one when the temporary access expires or is disabled, allowing the recipient of a temporary login to retain working…

  • CVE-2021-24836MedDec 13, 2021
    risk 0.28cvss 4.3epss 0.00

    The Temporary Login Without Password WordPress plugin before 1.7.1 does not have authorisation and CSRF checks when updating its settings, which could allows any logged-in users, such as subscribers to update them