WordPress Plugin Vulnerabilities

Single Sign On For TNG < 2.2.0 - Unauthenticated Arbitrary Password Reset

Description

The plugin does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
moonge
Submitter
moonge
Verified
Yes

Timeline

Publicly Published
2026-08-05 (about 25 days ago)
Added
2026-08-05 (about 24 days ago)
Last Updated
2026-08-28 (about 1 day ago)

Other