Credential Management Flaw in Temporary Login Plugin for WordPress by WPExtra
CVE-2026-77753
Currently unrated
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 12 September 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-77753?
The Temporary Login Without Password plugin for WordPress versions prior to 1.9.9 allows temporary users to create and retain Application Passwords. This vulnerability permits such users to maintain access via REST and XML-RPC even after temporary credentials should have expired or been revoked by the site administrator. If a user is granted temporary admin privileges, they could continue to access sensitive features, undermining site security and exposing it to further risks.
Affected Version(s)
Temporary Login Without Password 0 < 1.9.9
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.