Authentication Bypass Vulnerability in Single Sign On For TNG Plugin for WordPress
CVE-2026-15964

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 August 2026

What is CVE-2026-15964?

The Single Sign On For TNG plugin for WordPress poses a critical security risk as it allows unauthorized users to reset passwords without proper authentication. The vulnerability arises from the ssoprocess_ajax() function, which can be accessed without logging in, enabling attackers to supply their own email parameter and perform password resets on any user account, including those of administrators. A call to check_ajax_referer() is the only security measure in place, which is ineffective since the nonce is publicly available, allowing attackers to exploit it. This opens the door for complete site takeover, emphasizing the need for immediate security measures.

Affected Version(s)

Single Sign On For TNG 0 <= 2.0.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

andrea bocchetti
.