All verified exploits

CVE-2026-7567 Unauthenticated Admin Takeover via Temporary Login Token Type Confusion

Deterministic critical WordPress Added cve-verified-cve-2026-7567

Detects WordPress installs running the Temporary Login plugin (by Elementor) at version 1.0.0 or earlier. The maybe_login_temporary_user() hook on init reads the temp-login-token GET parameter without verifying it is a string. Sending the parameter as an array (?temp-login-token[]=x) bypasses the empty() guard, coerces sanitize_key() to return an empty string, and causes WordPress get_users() to ignore the empty meta_value and return the first user holding the _temporary_login_token meta. The plugin then issues a wordpress_logged_in_ cookie for that user. An unauthenticated remote attacker can take over the WordPress administrator account in a single GET request.

Related WordPress exploits

Is your app exploitable through CVE-2026-7567?

Scan your domain free