The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not perform any authorization or ownership checks before returning WooCommerce order metadata and the URLs of customer-uploaded attachments, allowing unauthenticated attackers to disclose other customers' order and attachment data. This vulnerability affects WordPress environments using the teddy-bear-customize-addon plugin. Defenders mana [truncated]
CRITICALteddy-bear-customize-addonCVE published 2026-09-11
The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, allowing unauthenticated attackers to upload arbitrary PHP files and execute code on the server. This critical vulnerability enables attackers to execute code on the server, potentially leading to unauthorized access, data breaches, and lateral movement within the network. Defenders should assess expos [truncated]
CRITICALteddy-bear-customize-addonCVE published 2026-09-11
The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, allowing unauthenticated attackers to log in as any registered user, including administrators, by supplying only that user's email address. This vulnerability affects WordPress installations using the teddy-bear-customize-addon plugin, potentially impacting confidentiality, integrity [truncated]