CVE-2026-7567Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Temporary Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.0.0. This is due to improper input validation in the maybe_login_temporary_user() function, which fails to verify that the 'temp-login-token' GET parameter is a scalar string before processing it. When the parameter is supplied as an array, PHP's empty() check is bypassed and sanitize_key() returns an empty string, which is then passed as the meta_value to get_users(). WordPress ignores an empty meta_value and returns all users matching the meta_key '_temporary_login_token', allowing authentication without a valid token. This makes it possible for unauthenticated attackers to authenticate as any active temporary login user by sending a single crafted GET request.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 13 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 11 signals
  • Disclosure: 7 classified signals
  • General: 3 classified signals
  • Peaked at 5 mentions on most recent observed day (2026-05-15)
  • 13 total mentions across 5 days

Deep dive

Activity timeline13 mentions / 5d
01345Mentions · 2026-05-01: 3Mentions · 2026-05-02: 2Mentions · 2026-05-03: 2Mentions · 2026-05-12: 1Mentions · 2026-05-15: 5Patch / Workaround · 2026-05-01: 1Patch / Workaround · 2026-05-02: 2Patch / Workaround · 2026-05-03: 1Patch / Workaround · 2026-05-12: 1Technical Details · 2026-05-01: 3Technical Details · 2026-05-02: 2Technical Details · 2026-05-03: 2Technical Details · 2026-05-12: 1Technical Details · 2026-05-15: 305-0105-0205-0305-1205-15
Signal classification3 categories
Disclosure
753.8%
Patch
323.1%
General
323.1%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-05-013
Disclosure2Patch1
2026-05-022
Disclosure1Patch1
2026-05-032
Disclosure2
2026-05-121
Patch1
2026-05-155
Disclosure2General3
Full discourse13 posts
  • kokumօtօ@__kokumoto
    Disclosure

    4万サイト以上が使用しているWordPressのTemporary Loginプラグインに重大(Critical)な脆弱性。CVE-2026-7567ばCVSSスコア9.8の認証回避。一時ログイントークンとして期待される文字列の代わりに配列を送ると諸々のチェックが効かずにログイン可能。バージョン1.1.0で修正。 https://securityonline.info/wordpress-temporary-login-cve-2026-7567-account-takeover-alert/

    Post summary

    The post announces a critical authentication bypass in WordPress Temporary Login plugin (CVE-2026-7567), describes the technical details, and notes that version 1.1.0 includes the fix.

    023155137.6K
    7.6K followersView on X
  • yousukezan@yousukezan
    Disclosure

    WordPressの人気プラグイン「Temporary Login」に深刻な欠陥が見つかり、認証なしで管理者権限に侵入される恐れが判明した。単純なリクエスト1回で突破可能なため、広範なサイトに影響が及ぶ危険性がある。 この脆弱性はCVE-2026-7567として追跡され、Temporary Loginのmaybe_login_temporary_user関数に起因する。通常は一時ログイントークンをGETパラメータで検証する仕組みだが、入力値が単一の文字列であるか確認していない点が問題となる。攻撃者が配列形式でパラメータを送信すると、empty関数の検証を回避し、sanitize_key関数は空文字を返す。この空値がWordPressのget_users関数に渡されることで、メタデータ条件が無視され、すべての一時ユーザーが取得対象となる。その結果、未認証のまま任意の一時ユーザーとしてログインでき、管理者権限を奪取される可能性がある。影響はバージョン1.0.0までの全環境に及び、修正は1.1.0で実施された。 https://securityonline.info/wordpress-temporary-login-cve-2026-7567-account-takeover-alert/

    Post summary

    The article announces the discovery of CVE‑2026‑7567 in the Temporary Login plugin, explains how the flaw allows unauthenticated administrators to be bypassed, and reports the patch released in version 1.1.0.

    010049196.8K
    14.4K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Patch

    🚨 تنبيه لأصحاب مواقع ومدونات (WordPress) إذا تستخدم أي من هذي الإضافات، حدثها فوراً! لأنها مصابة بثغرات حرجة جداً بتقييم (CVSS: 9.8). الإضافات المصابة: 1️⃣ إضافة (Temporary Login) | الثغرة: CVE-2026-7567 2️⃣ إضافة (User Registration) | الثغرة: CVE-2026-4882 3️⃣ إضافة (User Verification) | الثغرة: CVE-2026-7458

    Post summary

    The message warns WordPress site owners that three plugins contain CVE‑2026‑7567, CVE‑2026‑4882, and CVE‑2026‑7458 with high CVSS scores and advises them to update immediately.

    1301482.5K
    49.3K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    40,000+ Sites Exposed: Critical 9.8 CVSS Flaw Grants Total WordPress Account Takeover https://securityonline.info/wordpress-temporary-login-cve-2026-7567-account-takeover-alert/ CVE-2026-7567 https://nvd.nist.gov/vuln/detail/CVE-2026-7567

    Post summary

    The article announces a critical WordPress flaw (CVE‑2026‑7567) that can lead to full account takeover on over 40,000 sites, noting its high CVSS score but providing no PoC, exploit, or patch details.

    010411.2K
    11.7K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-7567-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text offers no concrete information about the CVE beyond a link and hashtags, thus no actionable details can be inferred.

    0001026
    215 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-7567 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    A short post that catalogs CVE‑2026‑7567 as a critical vulnerability with its CVSS details, but does not provide any PoC, exploit, patch, or evidence of active exploitation.

    1000033
    215 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-7567 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory The Temporary Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.0.0.

    Post summary

    A critical authentication bypass vulnerability (CVE-2026-7567) has been announced for the Temporary Login WordPress plugin, with a CVSS score of 9.8. The post provides technical details but no exploit code, patch, or evidence of active exploitation.

    1000041
    215 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-7567-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post merely links to an advisory page without providing any substantive information about the vulnerability, exploitation, or mitigation.

    0001025
    215 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVSS 9.8 CRITICAL · CVE-2026-7567 · 9.8 → 1.0.0 CVE: CVE-2026-7567 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces CVE‑2026‑7567 with a critical CVSS score and severity, but does not provide PoC, exploit, patch, or active exploitation details.

    1000043
    215 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-7567 — CVSS 9.8/10 ██████████ The Temporary Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.0.0.... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/0ELqKdjNLO

    Post summary

    The tweet alerts about a critical authentication bypass flaw (CVE-2026-7567) in the Temporary Login WordPress plugin (score 9.8) and urges vendors/owners to apply the patch immediately.

    1000059
    26 followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    WordPress Security Alert: CVE-2026-7567 Is a critical auth bypass in the Temporary Login plugin ≤ 1.0.0. What’s the risk: Attackers can log in as an active temporary user without a valid token, opening the door to admin abuse, malware injection, and store compromise. How to protect your site: Remove unused temporary users, disable the plugin until patched, audit recent logins, rotate credentials, and scan for suspicious file changes. https://quttera.com/wordpress-malware-scanner #WordPressSecurity #WooCommerce #CVE20267567 #PluginSecurity #AuthenticationBypass #EcommerceSecurity #WordPress #Malware #CVE #SilentRisk

    Post summary

    The post alerts about a critical authentication bypass in a WordPress plugin, outlines the risk, and urges users to disable the plugin and apply patches.

    0000061
    39 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7567 Authentication Bypass in Temporary Login Plugin for WordPr... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7567 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The text announces CVE‑2026‑7567, an authentication bypass in the Temporary Login Plugin for WordPress, with no additional details about PoC, exploitation, patching, or prevalence.

    0000063
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-7567 The Temporary Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.0.0. … CVSS 9.8 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-7567 #WordPress #CyberSecurity #InfoSec

    Post summary

    The tweet announces a critical authentication bypass flaw in the Temporary Login plugin for WordPress, with a high CVSS score, and notes that no patch is currently available.

    0000053
    460 followersView on X

Explore more