SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-14559

CRITICAL · CVSS 9.8 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The teddy-bear-customize-addon plugin for WordPress versions up to 1.0.5 is vulnerable due to a lack of password verification during user authentication, enabling unauthenticated attackers to gain access as any registered user, including those with administrative privileges, by simply providing the user's email address. This critical vulnerability poses a significant risk to WordPress sites utilizing this plugin, and all administrators should prioritize immediate updates or remediation to mitigate potential unauthorized access.

CVE
CVE-2026-14559
Severity
CRITICAL
CVSS
9.8
EPSS
0.28%
WordPress

Original NVD Description

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, allowing unauthenticated attackers to log in as any registered user, including administrators, by supplying only that user's email address.