← WordPress Vulnerabilities
WordPress security by component

teddy-bear-customize-addon

teddy-bear-customize-addon is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 10.

Plugin slug: teddy-bear-customize-addon

CVE-2026-14562: Teddy Bear Customize Addon exposes customer orders and attachments

teddy-bear-customize-addon through 1.0.5 performs no authorization or ownership check before returning WooCommerce order metadata and URLs for customer-uploaded attachments. An unauthenticated attacker can retrieve other customers' order and attachment data. The authoritative export does not identify the endpoint, action, order identifier, or attachment parameter.

PublishedSep 11, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for teddy-bear-customize-addon
Safe version
Sep 11, 2026 CVE-2026-14562
Teddy Bear Customize Addon exposes customer orders and attachments
teddy-bear-customize-addon through 1.0.5 performs no authorization or ownership check before returning WooCommerce order metadata and URLs for customer-uploaded attachments. An unauthenticated attacker can retrieve other customers' order and attachment data. The authoritative export does not identify the endpoint, action, order identifier, or attachment parameter.
See mitigation notes
CVE5.3
NVDPending
Sep 11, 2026 CVE-2026-14560
Teddy Bear Customize Addon permits unauthenticated PHP upload
teddy-bear-customize-addon through 1.0.5 validates uploads using a client-supplied content type and preserves the original filename. An unauthenticated attacker can upload an arbitrary PHP file and execute code on the WordPress server. The authoritative export does not identify the upload endpoint, action, file parameter, or destination path.
See mitigation notes
CVE10.0
NVDPending
Sep 11, 2026 CVE-2026-14559
Teddy Bear Customize Addon allows unauthenticated account takeover
teddy-bear-customize-addon through 1.0.5 authenticates a supplied email address without verifying the user's password. An unauthenticated attacker can log in as any registered user, including an Administrator. The authoritative export does not identify the action, email parameter, or authentication function.
See mitigation notes
CVE9.8
NVDPending