CVE-2026-15964 (matched: wordpress)

  • Saturday, 1st August, 2026
  • 16:04pm

A security flaw has been identified in the Single Sign On For TNG plugin for WordPress, affecting all versions of the plugin up to and including 2.0.0. This flaw allows anyone who visits your WordPress site, even if they are not logged in or have no authorized access to your site, to reset the password for any account on your site, including administrator accounts.

If an attacker exploits this flaw, they can gain full, unauthorized control of your WordPress site. This could let them change your site’s content, access sensitive information stored on the site, or use your site to spread harmful content to your visitors without your knowledge.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15964

« Back