A critical security flaw has been found in the Single Sign On For TNG plugin for WordPress, affecting all versions up to and including 2.0.0. This vulnerability lets any visitor who is not logged into your site reset the password for any WordPress account on your site, including administrator accounts.
The flaw exists because the plugin's password reset feature is open to all visitors without proper checks to confirm the person requesting the reset actually owns the target account. The only security check the plugin uses for this feature is broken: the code needed to pass that check is visible to every visitor to your site, so attackers can easily use it to exploit the flaw. If an attacker gains access to an administrator account, they will have full control of your WordPress site, allowing them to change content, steal private data, or take the site offline entirely.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15964