CRITICAL
9.8 CVE-2026-14559 Published 11 Sept 2026
WordPress teddy-bear-customize-addon Unauthenticated Login Bug
Worried this affects one of your servers?
The teddy-bear-customize-addon WordPress plugin, up to version 1.0.5, has a critical security flaw.
Attackers can log in as any registered user, including administrators, without providing a password. They only need the user's email address.
This vulnerability allows unauthorized access and potential site takeovers.
Reference: CVE-2026-14559 on NVD
← Back to Security News