CVE-2026-16299: Single Sign On For TNG < 2.2.0 - Unauthenticated Arbitrary Password Reset
Published Aug 10, 2026
·Updated
The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.
Affected Software
1 affected component
WordPress plugin Single Sign On For TNG<2.2.0
Event History
Aug 10, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-16299?
CVE-2026-16299 has a risk rating of 89, indicating a high severity level.
2
How do I fix CVE-2026-16299?
To fix CVE-2026-16299, update the Single Sign On For TNG plugin to version 2.2.0 or later.
3
What type of attack does CVE-2026-16299 enable?
CVE-2026-16299 allows unauthenticated attackers to perform arbitrary password resets on user accounts.
4
Can CVE-2026-16299 impact administrator accounts?
Yes, CVE-2026-16299 can allow attackers to reset the passwords of administrative accounts.
5
Is the Single Sign On For TNG plugin affected by CVE-2026-16299?
Yes, versions of the Single Sign On For TNG plugin prior to 2.2.0 are affected by CVE-2026-16299.