---
id: CVE-2026-15964
title: >-
  The Single Sign On For TNG plugin for WordPress is vulnerable to
  Authentication Bypass via unauthenticated password reset in all versions up
  to, and including, 2.0.0
summary: >-
  The Single Sign On For TNG plugin for WordPress is vulnerable to
  Authentication Bypass via unauthenticated password reset in all versions up
  to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function —
  registered on `wp_aj…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-620
published: '2026-08-01'
updated: '2026-08-01'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15964'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/single-sign-on-for-tng/tags/2.0.0/single-sign-on-for-tng.php#L102
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/single-sign-on-for-tng/tags/2.0.0/single-sign-on-for-tng.php#L120
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/single-sign-on-for-tng/tags/2.0.0/single-sign-on-for-tng.php#L69
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/single-sign-on-for-tng/tags/2.0.0/single-sign-on-for-tng.php#L96
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?reponame=&old=3624827%40single-sign-on-for-tng&new=3624827%40single-sign-on-for-tng
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/1d8d393e-764c-491d-8afb-7d4f8d0c387a?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - exploit-available
epss: 0.00625
epssPercentile: 0.4864
ingestedAt: '2026-08-02T05:17:48.214Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/Instructor-Admin/CVE-2026-15964-PoC'
  checkedAt: '2026-09-24T07:52:58.600Z'
exploitAvailable: true
---

## Overview

The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — registered on `wp_ajax_nopriv_ssoprocess_ajax` and therefore reachable without authentication — accepting an attacker-supplied `email` parameter with the `setnewpassword` operation and calling `reset_password()` on the resolved account without any ownership token, email confirmation link, or capability check. The sole guard is a call to `check_ajax_referer()`, which provides no authorization barrier because the `ssoajaxnonce` nonce is publicly broadcast on every front-end page via `wp_localize_script()` into the `SSOPWDREQUIREMENT` JavaScript object; since WordPress computes nonces for logged-out visitors against a shared anonymous session context, any unauthenticated visitor can scrape a valid nonce from the homepage and use it to authenticate the request. This makes it possible for unauthenticated attackers to change the password of any WordPress account, including administrator accounts, enabling complete site takeover.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
