logo

40,000+ Sites Exposed: Critical 9.8 CVSS Flaw Grants Total WordPress Account Takeover

ID: e93e9680-d7ca-5fbc-b676-c6814a155660

STIX ID: report--e93e9680-d7ca-5fbc-b676-c6814a155660

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-05-02

Date Updated: 2026-05-02

Author: Ddos

...
...

**Critical authentication bypass in Temporary Login (CVE-2026-7567, CVSS 9.8):** a flaw in the plugin's maybe_login_temporary_user() handling of the temp-login-token parameter allows an attacker to pass an array instead of a scalar, causing sanitization and metadata lookup failures that permit unauthenticated administrative login; users are advised to upgrade to version 1.1.0 or later.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.