WordPress Plugin Vulnerabilities

Single Sign On For TNG < 2.2.0 - Unauthenticated Arbitrary Password Reset

Description

The plugin does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
moonge
Submitter
moonge
Verified
Yes

Timeline

Publicly Published
2026-08-05 (about 2 months ago)
Added
2026-08-05 (about 2 months ago)
Last Updated
2026-10-08 (about 16 hours ago)

Other