The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, allowing unauthenticated attackers to log in as any registered user, including administrators, by supplying only that user's email address.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-11 07:16
Updated : 2026-09-11 17:35
NVD link : CVE-2026-14559
Mitre link : CVE-2026-14559
CVE.ORG link : CVE-2026-14559
JSON object : View
Products Affected
No product.
CWE
CWE-287
Improper Authentication
