CVE-2026-15964 (matched: wordpress)

  • Monday, 3rd August, 2026
  • 10:04am

This security notice applies to WordPress site owners who use the Single Sign On For TNG plugin, in all versions up to 2.0.0. The plugin has a critical flaw that allows anyone who visits your site to reset the password for any WordPress account on your site, including administrator accounts, without needing permission or confirmation.

The flaw exists because the plugin’s password reset tool can be accessed by unauthenticated visitors, and the security check meant to block unauthorized use is easily bypassed. The code required to pass that security check is publicly visible on every page of your site, so any visitor can collect it and use it to submit a password reset request for any account.

If an attacker exploits this issue, they can gain full control of your WordPress site. This lets them access all your site’s content and private data, make unauthorized changes, or use your site to harm visitors or other sites.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15964

« Back