CVE-2026-14559: Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Account Takeover
Published Sep 11, 2026
·Updated
The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, allowing unauthenticated attackers to log in as any registered user, including administrators, by supplying only that user's email address.
Affected Software
1 affected component
WordPress teddy-bear-customize-addon<=1.0.5
Event History
Sep 11, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Any unauthenticated attacker can exploit it if they know or can obtain the email address of a registered user. Administrator accounts are included among the affected targets.
2
What does an attacker need to take over an account?
The attacker only needs the email address associated with a registered account. The vulnerable plugin does not require verification of that account's password before authentication.
3
Which plugin versions are affected?
The issue affects teddy-bear-customize-addon through version 1.0.5.