CVE-2026-16299: Unknown Single Sign On For Tng

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

Affected products

  • Unknown Single Sign On For Tng: before 2.2.0 (fixed in 2.2.0)

Published 2026-08-10. Last modified 2026-08-26.