External risk intelligence

Single Sign On For TNG WordPress Plugin Password Reset Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-16299

The vulnerability affects a WordPress plugin responsible for Single Sign-On (SSO) authentication. Such components are integrated directly into public-facing web login portals, making them accessible to any user or attacker over the internet as part of the standard authentication flow.

Authentication Bypass

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability impacts a WordPress plugin designed for Single Sign-On (SSO), potentially allowing unauthorized individuals to reset user passwords, including administrative accounts. This could grant attackers full control over the affected website. The primary concern is to confirm if this specific plugin is in use and, if so, to assess exposure.

  • Unauthenticated users can reset any password.
  • Website control can be fully compromised.
  • Confirm plugin use and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker can compromise a WordPress site by exploiting a flaw in the password reset process of the Single Sign On For TNG plugin. This vulnerability allows an unauthenticated attacker to reset the password for any user, including administrators, by simply initiating a password reset. If successful, this could grant the attacker full control over the website.

  • No authentication required.
  • User initiates password reset.
  • Complete site takeover.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated attackers could reset the passwords of any user, including administrators, of websites using the affected Single Sign On For TNG WordPress plugin. This could allow an attacker to gain full control of the website.

  • User account credentials.
  • Password reset process.
  • Complete website takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Single Sign On For TNG WordPress plugin's vulnerability requires immediate attention from teams responsible for website security and application management. The first practical step is to identify all instances of this plugin across your WordPress deployments, confirm their accessibility from the internet, and determine their criticality to business operations. Once identified, work with the accountable application owner to plan a risk-based remediation strategy, which may involve coordinating with the plugin vendor.

  • Owner: Website application owners.
  • Verify: Internet exposure and business criticality.
  • Action: Plan vendor-assisted remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Single Sign On For TNG WordPress plugin?

This plugin is an add-on for WordPress sites that manages Single Sign-On (SSO) authentication. It allows users to log in using external identity providers instead of standard WordPress credentials, streamlining the authentication process for site members and administrators.

What does CVE-2026-16299 mean for security?

This vulnerability is classified as Improper Authentication (CWE-287). It means the plugin fails to verify the legitimacy of a password reset request. Because of this flaw, the system blindly accepts requests to change account credentials, effectively bypassing the identity verification steps usually required to maintain secure user access.

How can an attacker trigger this vulnerability?

An attacker initiates the attack by sending a crafted password reset request to the affected plugin. No special permissions or prior access are needed. It is important to note that this bug is not triggered by normal, authorized user password changes, but specifically through the flawed automated reset flow provided by the plugin.

Do I need to worry if my site is internal only?

According to Halo Surface Signal, this vulnerability is particularly dangerous because the plugin integrates directly into public-facing login portals. While any deployment is at risk, sites accessible over the internet are the primary target because attackers can reach the vulnerable reset functionality without needing network-level access to your internal infrastructure.

When should I take action to secure my WordPress site?

You should act immediately by locating all WordPress installations using this plugin. Confirm whether the plugin is running an affected version and verify if the site is reachable online. Once you have identified all instances, coordinate with your site administrators to plan a remediation strategy, which will likely involve updating the plugin or coordinating with the vendor.

References