CVE-2026-15964 (matched: wordpress)

  • Sunday, 2nd August, 2026
  • 16:03pm

A security vulnerability, tracked as CVE-2026-15964, has been discovered in the Single Sign On For TNG plugin for WordPress, impacting all versions up to and including version 2.0.0. This flaw allows anyone who is not logged into your website to reset the password for any WordPress account on the site, including administrator accounts, without needing approval from the account’s owner.

The vulnerability exists because the plugin’s password reset feature does not verify that the person requesting the change has permission to access the target account. A security check designed to block unauthorized requests is ineffective, as the code needed to pass this check is publicly visible on every public page of the site, so any visitor can collect it and use it to exploit the flaw.

If an attacker successfully changes an administrator’s password, they can take full control of your entire WordPress site, accessing all its content, user data, and settings.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15964

« Back