


Perceptive Security
SOC/SIEM Consultancy

The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, …
Published:
1 August 2026 at 00:00:00
Alert date:
1 August 2026 at 12:00:52
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Zero-Day Vulnerabilities
The Single Sign On For TNG plugin for WordPress (versions up to and including 2.0.0) contains a critical authentication bypass vulnerability via unauthenticated password reset. The vulnerable ssoprocess_ajax() function is registered on the nopriv AJAX hook, making it accessible without authentication. An attacker can supply any email address with the setnewpassword operation to reset any account's password, including administrators. The only protection is a nonce check, which is ineffective because the nonce is publicly exposed on every front-end page via wp_localize_script(). Since WordPress generates nonces for logged-out users against a shared anonymous session, any visitor can scrape a valid nonce and use it to perform the attack. This enables complete site takeover by unauthenticated attackers. No ownership token, email confirmation, or capability check is performed before executing the password reset.
Technical details
Mitigation steps:
Affected products:
Single Sign On For TNG WordPress Plugin 2.0.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-15964
https://plugins.trac.wordpress.org/browser/single-sign-on-for-tng/tags/2.0.0/single-sign-on-for-tng.php#L102
https://plugins.trac.wordpress.org/browser/single-sign-on-for-tng/tags/2.0.0/single-sign-on-for-tng.php#L120
https://plugins.trac.wordpress.org/browser/single-sign-on-for-tng/tags/2.0.0/single-sign-on-for-tng.php#L69
https://plugins.trac.wordpress.org/browser/single-sign-on-for-tng/tags/2.0.0/single-sign-on-for-tng.php#L96
https://plugins.trac.wordpress.org/changeset?reponame=&old=3624827%40single-sign-on-for-tng&new=3624827%40single-sign-on-for-tng
https://www.wordfence.com/threat-intel/vulnerabilities/id/1d8d393e-764c-491d-8afb-7d4f8d0c387a?source=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
