Description
The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, allowing unauthenticated attackers to log in as any registered user, including administrators, by supplying only that user's email address.
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated account takeover
Action: Patch or Disable
AI Analysis

Impact

The teddy‑bear‑customize‑addon plugin for WordPress fails to verify a user’s password during authentication, allowing an unauthenticated attacker to log in as any registered user—including administrators—by supplying only a legitimate user’s e‑mail address. This authentication bypass constitutes a full account takeover, giving the attacker immediate control over the site and its contents. The weakness is classified as CWE‑287.

Affected Systems

Any WordPress installation that has installed the teddy‑bear‑customize‑addon plugin version 1.0.5 or earlier is affected. The vulnerability exists in all releases up to and including 1.0.5; later versions are not known to be vulnerable. Administrators and all content editors with valid account credentials are at risk when the plugin is present.

Risk and Exploitability

The flaw permits remote attackers to bypass authentication over the public network by sending a login request that contains only a legitimate user’s e‑mail address. Because the CVSS score is 9.8, the vulnerability is considered critical. The EPSS score of 0.00136 indicates a very low but non‑zero exploitation probability, but the lack of a password check makes this an attractive attack vector for attackers targeting WordPress sites. The vulnerability is not listed in the CISA KEV catalog, but the potential impact remains high due to the nature of the authentication bypass.

Generated by OpenCVE AI on September 11, 2026 at 16:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the teddy‑bear‑customize‑addon plugin to any version newer than 1.0.5 that includes the authentication fix; if no update is available, deactivate or delete the plugin to remove the vulnerability.
  • After applying the fix, reset passwords for all administrator accounts, enforce a strong password policy, and enable two‑factor authentication to reduce the risk of future unauthorized access.
  • Monitor authentication logs and user activity for suspicious logins, and consider restricting access to the WordPress admin area by IP or using a security plugin that limits login attempts.

Generated by OpenCVE AI on September 11, 2026 at 16:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-286

Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-286

Fri, 11 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, allowing unauthenticated attackers to log in as any registered user, including administrators, by supplying only that user's email address.
Title Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Account Takeover
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-11T10:11:16.879Z

Reserved: 2026-07-03T09:47:23.295Z

Link: CVE-2026-14559

cve-icon Vulnrichment

Updated: 2026-09-11T10:07:04.426Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T07:16:45.877

Modified: 2026-09-11T17:35:21.440

Link: CVE-2026-14559

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T16:45:14Z

Weaknesses