VYPR

Single Sign On For TNG

by WordPress

CVEs (2)

  • CVE-2026-16299CriAug 10, 2026
    risk 0.64cvss 9.8epss 0.00

    The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

  • CVE-2026-15964CriAug 1, 2026
    risk 0.64cvss 9.8epss 0.01

    The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — registered on `wp_ajax_nopriv_ssoprocess_ajax` and therefore…