CVE-2026-15964 (matched: wordpress)

  • Saturday, 1st August, 2026
  • 10:05am

A security flaw has been found in the Single Sign On For TNG plugin for WordPress, which impacts all versions of the plugin up to and including version 2.0.0. This vulnerability lets people who do not have a login for your site reset the password for any user account on your WordPress site, including administrator accounts. If an attacker exploits this flaw, they can take full, unauthorized control of your entire website.

The issue exists because a public feature of the plugin that handles password reset requests can be accessed by anyone, even without logging in, and does not verify that the person making the request is allowed to change the target account's password. The small security check the plugin uses to validate these requests is publicly visible to every visitor to your site, making it easy for attackers to abuse this functionality to gain access.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15964

« Back