A security flaw has been found in the Single Sign On For TNG plugin for WordPress, impacting all versions of the plugin up to and including 2.0.0. This issue allows any person who visits your site (even if they do not have a user account for your WordPress site) to reset the password for any existing account on the site, including administrator accounts.
The vulnerability exists because a small verification code used to confirm legitimate site requests is publicly visible to all visitors, and there is no extra check to confirm the person requesting a password reset actually has access to the email address linked to the account. If an attacker exploits this flaw, they can gain full control of your WordPress site, letting them make unauthorized changes, access private content, or take other harmful actions.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15964