CVE-2026-14559

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, allowing unauthenticated attackers to log in as any registered user, including administrators, by supplying only that user's email address.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-11 07:16

Updated : 2026-09-11 17:35


NVD link : CVE-2026-14559

Mitre link : CVE-2026-14559

CVE.ORG link : CVE-2026-14559


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication