CRITICAL 9.8 CVE-2026-14559 Published 11 Sept 2026

WordPress teddy-bear-customize-addon Unauthenticated Login Bug

Worried this affects one of your servers?

The teddy-bear-customize-addon WordPress plugin, up to version 1.0.5, has a critical security flaw.

Attackers can log in as any registered user, including administrators, without providing a password. They only need the user's email address.

This vulnerability allows unauthorized access and potential site takeovers.

Reference: CVE-2026-14559 on NVD

← Back to Security News