CVE-2026-15964 is a critical authentication bypass vulnerability in the Single Sign On For TNG plugin for WordPress affecting all versions up to and including 2.0.0. The flaw resides in the plugin’s ssoprocess_ajax() function, which is exposed to unauthenticated users through the wp_ajax_nopriv_ssoprocess_ajax AJAX action. When invoked with the setnewpassword operation, the function accepts an attacker-controlled email parameter and calls reset_password() for the resolved WordPress account without verifying account ownership, requiring an out-of-band password reset token, enforcing an email confirmation flow, or performing a capability check. The implementation relies only on check_ajax_referer() for request validation, but the required nonce is publicly exposed on front-end pages through wp_localize_script() in a JavaScript object. Because logged-out visitors can obtain a valid nonce from public pages, an unauthenticated attacker can submit a forged password reset request for arbitrary accounts. This enables takeover of any targeted WordPress user account, including administrators.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a standalone Python exploit and a separate non-destructive checker for CVE-2026-15964 affecting the WordPress Single Sign On For TNG plugin <= 2.0.0. Structure is small and focused: the main exploit file (CVE-2026-15964.py) performs nonce scraping from the front page, then sends a POST to /wp-admin/admin-ajax.php with action=ssoprocess_ajax and operation=setnewpassword to reset any user password without authentication. It supports scrape-only, passive check, enum-only, and full password-change modes. The checker (CVE-2026-15964-checker.py) is a bulk assessment tool that fingerprints WordPress/plugin presence, fetches the plugin readme.txt to parse the Stable tag, and optionally performs a safe behavioral probe using a non-existent email to distinguish vulnerable 2.0.0 behavior from patched 2.1.0 behavior. tests/mock_server.py is a localhost-only harness that simulates vulnerable, patched, WordPress-without-plugin, and non-WordPress responses for validation. The exploit’s main capability is unauthenticated password reset leading to full site takeover; additional intelligence includes account enumeration and a documented bonus unauthenticated option write via operation=set_tzoffset. This is a real, operational PoC rather than a framework module or mere detector.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.