A security vulnerability has been identified in the Single Sign On For TNG plugin for WordPress, impacting all versions up to and including 2.0.0. This flaw allows anyone who visits your website, even without a login or user account, to reset the password for any user on your WordPress site, including administrator accounts. The issue exists because the plugin's password reset process does not verify that the person requesting the change is authorized to do so.
If an attacker exploits this vulnerability to gain access to an administrator account, they can take full control of your website. This allows them to make unauthorized changes to your site's content and settings, or take other actions that negatively affect your site and its visitors.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15964