WordPress security by component
teddy-bear-customize-addon
teddy-bear-customize-addon is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 10.
Plugin slug:
teddy-bear-customize-addonLatest vulnerability
CVE-2026-14562: Teddy Bear Customize Addon exposes customer orders and attachments
teddy-bear-customize-addon through 1.0.5 performs no authorization or ownership check before returning WooCommerce order metadata and URLs for customer-uploaded attachments. An unauthenticated attacker can retrieve other customers' order and attachment data. The authoritative export does not identify the endpoint, action, order identifier, or attachment parameter.
| Safe version |
|
||
|---|---|---|---|
| Sep 11, 2026 |
CVE-2026-14562
Teddy Bear Customize Addon exposes customer orders and attachments
teddy-bear-customize-addon through 1.0.5 performs no authorization or ownership check before returning WooCommerce order metadata and URLs for customer-uploaded attachments. An unauthenticated attacker can retrieve other customers' order and attachment data. The authoritative export does not identify the endpoint, action, order identifier, or attachment parameter.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Sep 11, 2026 |
CVE-2026-14560
Teddy Bear Customize Addon permits unauthenticated PHP upload
teddy-bear-customize-addon through 1.0.5 validates uploads using a client-supplied content type and preserves the original filename. An unauthenticated attacker can upload an arbitrary PHP file and execute code on the WordPress server. The authoritative export does not identify the upload endpoint, action, file parameter, or destination path.
|
See mitigation notes |
CVE10.0
NVDPending
|
| Sep 11, 2026 |
CVE-2026-14559
Teddy Bear Customize Addon allows unauthenticated account takeover
teddy-bear-customize-addon through 1.0.5 authenticates a supplied email address without verifying the user's password. An unauthenticated attacker can log in as any registered user, including an Administrator. The authoritative export does not identify the action, email parameter, or authentication function.
|
See mitigation notes |
CVE9.8
NVDPending
|