WordPress Plugin Vulnerabilities

Single Sign On For TNG < 2.2.0 - Unauthenticated Arbitrary Password Reset

Description

The plugin does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
moonge
Submitter
moonge
Verified
Yes

Timeline

Publicly Published
2026-08-05 (about 5 days ago)
Added
2026-08-05 (about 4 days ago)
Last Updated
2026-08-07 (about 2 days ago)

Other