{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/single-sign-on-for-tng--2.0.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-15964"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Single Sign On For TNG (\u003c= 2.0.0)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Single Sign On For TNG plugin for WordPress, in versions up to and including 2.0.0, contains a critical authentication bypass vulnerability (CVE-2026-15964). The flaw resides in the \u003ccode\u003essoprocess_ajax()\u003c/code\u003e function, which is exposed to unauthenticated users via the \u003ccode\u003ewp_ajax_nopriv_ssoprocess_ajax\u003c/code\u003e action. By submitting a \u003ccode\u003esetnewpassword\u003c/code\u003e operation along with a target user's email address, an attacker can trigger the \u003ccode\u003ereset_password()\u003c/code\u003e function without any ownership verification, such as an email confirmation or security token.\u003c/p\u003e\n\u003cp\u003eAlthough the function attempts to implement a CSRF guard using \u003ccode\u003echeck_ajax_referer()\u003c/code\u003e, the required \u003ccode\u003essoajaxnonce\u003c/code\u003e is exposed globally to all visitors via the \u003ccode\u003eSSOPWDREQUIREMENT\u003c/code\u003e JavaScript object injected into front-end pages. Because WordPress generates nonces for unauthenticated sessions, an attacker can scrape this value from the site's homepage and successfully authorize their malicious password reset request. This vulnerability enables unauthenticated attackers to hijack any user account, including administrative accounts, resulting in complete site takeover.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker navigates to the public-facing homepage of the target WordPress site.\u003c/li\u003e\n\u003cli\u003eAttacker inspects the HTML source or JavaScript objects to retrieve the \u003ccode\u003eSSOPWDREQUIREMENT\u003c/code\u003e object containing the \u003ccode\u003essoajaxnonce\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP POST request to the WordPress \u003ccode\u003eadmin-ajax.php\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker includes the \u003ccode\u003eaction\u003c/code\u003e parameter set to \u003ccode\u003essoprocess_ajax\u003c/code\u003e and the \u003ccode\u003eoperation\u003c/code\u003e parameter set to \u003ccode\u003esetnewpassword\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker provides the \u003ccode\u003eemail\u003c/code\u003e parameter corresponding to the target administrative or privileged account.\u003c/li\u003e\n\u003cli\u003eAttacker includes the scraped \u003ccode\u003essoajaxnonce\u003c/code\u003e in the request headers or body to satisfy \u003ccode\u003echeck_ajax_referer()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe plugin executes \u003ccode\u003ereset_password()\u003c/code\u003e for the specified email account, overwriting the legitimate password.\u003c/li\u003e\n\u003cli\u003eAttacker logs into the target account with the new password to achieve full site takeover.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-15964 allows an unauthenticated attacker to reset the password of any user registered on the WordPress instance. If a site administrator's email is known, the attacker can gain full administrative control, leading to potential data exfiltration, injection of malicious payloads into the site, or complete site defacement. This vulnerability affects all installations of the plugin version 2.0.0 and earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately update the \u0026quot;Single Sign On For TNG\u0026quot; plugin to the latest patched version available.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious POST requests to \u003ccode\u003eadmin-ajax.php\u003c/code\u003e where the \u003ccode\u003eaction\u003c/code\u003e parameter is \u003ccode\u003essoprocess_ajax\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAudit WordPress user accounts for unexpected password resets or unauthorized account activity.\u003c/li\u003e\n\u003cli\u003eDisable the plugin functionality if an immediate update is not feasible.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-01T09:49:47Z","date_published":"2026-08-01T09:49:47Z","id":"https://feed.craftedsignal.io/briefs/2026-08-tng-auth-bypass/","summary":"An unauthenticated password reset vulnerability in the Single Sign On For TNG plugin (CVE-2026-15964) allows attackers to perform full site takeover by bypassing AJAX nonce protections.","title":"Authentication Bypass in Single Sign On For TNG WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-tng-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Single Sign on for TNG (\u003c= 2.0.0)","version":"https://jsonfeed.org/version/1.1"}