Temporary Login <= 1.0.0 - Authentication Bypass to Account Takeover
criticalThe Temporary Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.0.0. This is due to improper input validation in the maybe_login_temporary_user() function, which fails to verify that the 'temp-login-token' GET parameter is a scalar string before processing it. When the...
- CVSS:
- 9.8
- Affected:
- up to 1.0.0
- Fixed in:
- 1.1.0
- Disclosed:
- Apr 30, 2026