Unrated severityNVD Advisory· Published Sep 11, 2026
CVE-2026-14562
CVE-2026-14562
Description
The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not perform any authorization or ownership checks before returning WooCommerce order metadata and the URLs of customer-uploaded attachments, allowing unauthenticated attackers to disclose other customers' order and attachment data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=1.0.5
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.