Detects WordPress installs running the Temporary Login plugin (by Elementor) at version 1.0.0 or earlier. The maybe_login_temporary_user() hook on init reads the temp-login-token GET parameter without verifying it is a string. Sending the parameter as an array (?temp-login-token[]=x) bypasses the empty() guard, coerces sanitize_key() to return an empty string, and causes WordPress get_users() to ignore the empty meta_value and return the first user holding the _temporary_login_token meta. The plugin then issues a wordpress_logged_in_ cookie for that user. An unauthenticated remote attacker can take over the WordPress administrator account in a single GET request.
Is your app exploitable through CVE-2026-7567?
Scan your domain free