What is CVE-2026-16299?
CVE-2026-16299 is a critical vulnerability in the 'Single Sign On For TNG' WordPress plugin before version 2.2.0, where improper validation of password reset requests allows unauthenticated attackers to reset the password of any user, including administrators. This could lead to a full site takeover, and immediate update to version 2.2.0 or later is strongly recommended.
Azərbaycanca: CVE-2026-16299, 'Single Sign On For TNG' WordPress plaqininin 2.2.0-dan əvvəlki versiyalarında parol sıfırlama sorğusunun düzgün yoxlanılmaması səbəbindən autentifikasiya olunmamış hücumçuların istənilən istifadəçinin, o cümlədən administratorun parolunu sıfırlamasına imkan verən kritik bir boşluqdur. Bu, saytın tam ələ keçirilməsinə səbəb ola bilər, dərhal plaqini ən son 2.2.0 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which versions of the 'Single Sign On For TNG' plugin are affected by CVE-2026-16299?
All versions of the 'Single Sign On For TNG' WordPress plugin before version 2.2.0 are affected by this critical vulnerability.
What can an unauthenticated attacker achieve by exploiting CVE-2026-16299?
An unauthenticated attacker can reset the password of any user, including administrators, due to improper validation of password reset requests, potentially leading to a full site takeover.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.