PT-2026-90561 · Undefined · Undefined
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Temporary Login Without Password versions prior to 1.9.9
Description
The plugin fails to verify if the user requesting a temporary login possesses network super admin rights before granting those privileges to the new account. This flaw allows an administrator of a single site within a multisite network to gain control over the entire network. Additionally, the lack of this check enables the promotion of existing accounts, including those belonging to an attacker.
Recommendations
Update to version 1.9.9 or later.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined