CVE-2026-15964 (matched: wordpress)

  • Sunday, 2nd August, 2026
  • 04:04am

A security flaw has been found in the Single Sign On For TNG plugin for WordPress. All versions of this plugin up to and including version 2.0.0 have an authentication bypass vulnerability, meaning anyone who visits your website (even if they are not logged into your WordPress dashboard) can reset the password for any account on the site, including administrator accounts. If exploited, this lets an attacker take full, unauthorized control of your entire WordPress website.

The flaw works because the plugin's password reset feature does not require standard proof of account ownership, such as a confirmation link sent to the account's registered email address, before changing a password. A security check meant to block unauthorized reset requests uses a verification code that is publicly visible on every page of your site, so any visitor can grab this code and use it to carry out the attack.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15964

« Back