How to handle admin and passwords requests from plugins developers?

No one else should touch your live site.

What you should do: Create an exact copy of your site, preferably on the same server, so the software context is the same. This second site is the test site that should run with the same theme, plugins, content and WordPress version as the live site. It should, of course also show the same problem.

Protect that site per .htaccess or a similar sever configuration with a password to keep it out of reach for other visitors and bots.

Create a separate admin user for the developer there, then let her solve that problem and explain the solution, so you can apply it on your own to the live site.