plugin

Single Sign On For Tng Vulnerabilities

1 known security issue reported for the Single Sign On For Tng WordPress plugin. Most recent disclosed Jul 31, 2026.

1 critical

Running Single Sign On For Tng on your site? Check whether your installed version is affected.

Scan your site free

Single Sign On For TNG <= 2.0.0 - Unauthenticated Privilege Escalation via Unverified Password Change

critical

The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — registered on `wp_ajax_nopriv_ssoprocess_ajax` and therefore reachable without authentication — accepti...

CVSS:
9.8
Affected:
up to 2.0.0
Fixed in:
2.1.0
Disclosed:
Jul 31, 2026

CVE-2026-15964 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database