Temporary Login Without Password

Temporary Login Without Password has one disclosed vulnerability in the WordSec catalog, all reported in 2021; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Incorrect Authorization, behind 1 of the records (100%).

The one issue recorded for Temporary Login Without Password has a vendor fix available, so running the current release closes it.

All of these findings were reported by apple502j. Temporary Login Without Password is installed on roughly 100,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Temporary Login Without Password vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.3CVE-2021-24836

Temporary Login Without Password <= 1.7.0 - Subscriber+ Plugin Settings Update

Read the full analysis

Vulnerability Records

1 records
Temporary Login Without Password banner
Latestv1.9.9

Temporary Login Without Password

storeapps

Author

storeapps

5.0(1,539)
100/100
Last Updated
2026-09-09 (4d ago)
Active Installs
100,000+
Downloads
2,013,182
Requires WP
3.0.1+
Requires PHP
5.3+
Tested up to
WP 7.1
Created
2016-08-03 (10y ago)

Temporary Login Without Password lets you create a self-expiring login link and share it with a developer, support agent, or guest editor — instead of handing over your username and password. The person just clicks the link and they’re logged in. No account setup, no shared credentials, no password to remember or revoke later. You choose the role and the expiry, and access shuts off automatically when the time is up. How it helps Every time you share your real admin login with an outside developer, you’re trusting them with permanent access — and you have to remember to change the password after. TLWP removes that risk entirely. Generate a link, set it to expire in an hour, a day, or a custom date, and you’re done. Benefits Create unlimited temporary logins Assign any WordPress role to a temporary account No username or password needed — login is just a click Set expiry by time (hour, day, week, month) or a custom date Redirect the user to a specific page after login Set a language for the temporary user See last login time and number of times accessed Track what each temporary user did with detailed activity logs Who this is for Site owners who need to give a developer quick access without sharing real credentials Agencies onboarding client sites for support or maintenance Bloggers giving guest writers or editors short-term review access Developers who want a clean, auditable way to request site access from clients For Developers If you need admin access to a client’s WordPress site to resolve an issue, send them this: Hi {%customer_name%}, To allow me to investigate your site, please install the free plugin Temporary Login Without Password, and share the temporary admin link it generates. Once I have access, I’ll check the site and try to resolve the issue. Note: Set the expiry to one month, and send me the generated link as a reply to this email. TLWP Pro Free covers the essentials. Pro adds: Limit link usage — cap how many times a login link can be used Instant admin alerts — get notified every time a temporary login is accessed Full activity log — see exactly what actions each temporary user performed Upgrade to TLWP Pro Our other plugins Icegram Express — newsletter plugin for leads, broadcasts, and automated post notifications Icegram Mailer — reliable email delivery for WordPress & WooCommerce Icegram Engage — popups, welcome bar, and opt-ins Post / Page Duplicate — one-click content duplicator Switch User Login — switch between WordPress accounts from the admin bar

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C