CVE-2026-14559
The WordPress plugin teddy‑bear‑customize‑addon, versions up to 1.0.5, fails to check a user’s password during login. This flaw lets anyone who knows a user’s email address log in as that user, including administrators, without needing a password.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
WordPress sites that have installed the teddy‑bear‑customize‑addon plugin version 1.0.5 or earlier.
Real-world impact
An attacker can hijack any user account, gain administrative control of the WordPress site, and modify or delete content, install malware, or steal sensitive data.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability is exploitable over the network, requires no special privileges or user interaction, and gives an attacker full confidentiality, integrity, and availability impact.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources