Executive brief
The Teddy Bear Customize Addon WordPress plugin fails to verify user passwords during login, allowing attackers to gain unauthorized access to any user account—including administrator accounts—by providing only an email address. This vulnerability enables complete account takeover and administrative access without valid credentials, putting all website data and functionality at risk.
Technical details
The plugin contains an authentication bypass vulnerability (CWE-287: Improper Authentication) in its login mechanism. The vulnerable component fails to validate the user's password before granting authentication, requiring only knowledge of a valid email address registered on the WordPress instance. The attack is network-reachable and requires no prior authentication or user interaction. An attacker can exploit this to assume the identity of any user, including administrators, and perform any action the compromised account permits. No patch is currently available for versions through 1.0.5.
Affected products
- HocWP Team Teddy Bear Customize Addon through 1.0.5
Timeline
- 2026-09-09: disclosed
- 2026-09-11: advisory