← Back to browse · API

CVE-2026-7567

Severity
CRITICAL
CVSS
9.8
EPSS
0.09246
Risk score
42.44
CISA KEV
No
PoC
No
Published
2026-05-01
Modified
2026-05-01
First seen
2026-08-07
Aliases
EUVD-2026-26490, GHSA-4V98-7R2C-MXG7
Products
elemntor:Temporary Login 0 ≤1.0.0
Sources
euvd EUVD-2026-26490

Description

The Temporary Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.0.0. This is due to improper input validation in the maybe_login_temporary_user() function, which fails to verify that the 'temp-login-token' GET parameter is a scalar string before processing it. When the parameter is supplied as an array, PHP's empty() check is bypassed and sanitize_key() returns an empty string, which is then passed as the meta_value to get_users(). WordPress ignores an empty meta_value and returns all users matching the meta_key '_temporary_login_token', allowing authentication without a valid token. This makes it possible for unauthenticated attackers to authenticate as any active temporary login user by sending a single crafted GET request.

References