Impact
The teddy‑bear‑customize‑addon plugin for WordPress fails to verify a user’s password during authentication, allowing an unauthenticated attacker to log in as any registered user—including administrators—by supplying only a legitimate user’s e‑mail address. This authentication bypass constitutes a full account takeover, giving the attacker immediate control over the site and its contents. The weakness is classified as CWE‑287.
Affected Systems
Any WordPress installation that has installed the teddy‑bear‑customize‑addon plugin version 1.0.5 or earlier is affected. The vulnerability exists in all releases up to and including 1.0.5; later versions are not known to be vulnerable. Administrators and all content editors with valid account credentials are at risk when the plugin is present.
Risk and Exploitability
The flaw permits remote attackers to bypass authentication over the public network by sending a login request that contains only a legitimate user’s e‑mail address. Because the CVSS score is 9.8, the vulnerability is considered critical. The EPSS score of 0.00136 indicates a very low but non‑zero exploitation probability, but the lack of a password check makes this an attractive attack vector for attackers targeting WordPress sites. The vulnerability is not listed in the CISA KEV catalog, but the potential impact remains high due to the nature of the authentication bypass.
OpenCVE Enrichment