40,000+ Sites Exposed: Critical 9.8 CVSS Flaw Grants Total WordPress Account Takeover
ID: e93e9680-d7ca-5fbc-b676-c6814a155660
STIX ID: report--e93e9680-d7ca-5fbc-b676-c6814a155660
Feed Name: securityonline.info
Threat Score
**Critical authentication bypass in Temporary Login (CVE-2026-7567, CVSS 9.8):** a flaw in the plugin's maybe_login_temporary_user() handling of the temp-login-token parameter allows an attacker to pass an array instead of a scalar, causing sanitization and metadata lookup failures that permit unauthenticated administrative login; users are advised to upgrade to version 1.1.0 or later.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
