A security flaw has been identified in the Single Sign On For TNG plugin for WordPress, impacting all versions up to and including 2.0.0. This flaw allows anyone who does not have a login for your WordPress site to reset the password for any existing user on the site, including administrator accounts. If an attacker exploits this vulnerability, they can gain full control of your site, modify its content, or access any data stored on it.
The flaw exists because a standard security token used to verify legitimate site requests is publicly visible to all visitors on your site’s public pages. Attackers can use this publicly available token to bypass the normal checks that are supposed to stop unauthorized users from changing other people’s passwords. Any WordPress site running the Single Sign On For TNG plugin at version 2.0.0 or lower is exposed to this risk.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15964