Undefined · Undefined · CVE-2026-77752
**Name of the Vulnerable Software and Affected Versions**
Temporary Login Without Password versions prior to 1.9.9
**Description**
The plugin fails to verify if the user requesting a temporary login possesses network super admin rights before granting those privileges to the new account. This flaw allows an administrator of a single site within a multisite network to gain control over the entire network. Additionally, the lack of this check enables the promotion of existing accounts, including those belonging to an attacker.
**Recommendations**
Update to version 1.9.9 or later.