PatchSiren

teddy-bear-customize-addon CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM teddy-bear-customize-addon CVE published 2026-09-11

CVE-2026-14562

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not perform any authorization or ownership checks before returning WooCommerce order metadata and the URLs of customer-uploaded attachments, allowing unauthenticated attackers to disclose other customers' order and attachment data. This vulnerability affects WordPress environments using the teddy-bear-customize-addon plugin. Defenders mana [truncated]

CRITICAL teddy-bear-customize-addon CVE published 2026-09-11

CVE-2026-14560

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, allowing unauthenticated attackers to upload arbitrary PHP files and execute code on the server. This critical vulnerability enables attackers to execute code on the server, potentially leading to unauthorized access, data breaches, and lateral movement within the network. Defenders should assess expos [truncated]

CRITICAL teddy-bear-customize-addon CVE published 2026-09-11

CVE-2026-14559

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, allowing unauthenticated attackers to log in as any registered user, including administrators, by supplying only that user's email address. This vulnerability affects WordPress installations using the teddy-bear-customize-addon plugin, potentially impacting confidentiality, integrity [truncated]