Authentication Bypass Vulnerability in Single Sign On For TNG Plugin for WordPress
CVE-2026-15964
9.8CRITICAL
What is CVE-2026-15964?
The Single Sign On For TNG plugin for WordPress poses a critical security risk as it allows unauthorized users to reset passwords without proper authentication. The vulnerability arises from the ssoprocess_ajax() function, which can be accessed without logging in, enabling attackers to supply their own email parameter and perform password resets on any user account, including those of administrators. A call to check_ajax_referer() is the only security measure in place, which is ineffective since the nonce is publicly available, allowing attackers to exploit it. This opens the door for complete site takeover, emphasizing the need for immediate security measures.
Affected Version(s)
Single Sign On For TNG 0 <= 2.0.0