VYPR

Teddy Bear Customize Addon

by WordPress

CVEs (3)

  • CVE-2026-14562Sep 11, 2026
    risk 0.00cvss epss

    The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not perform any authorization or ownership checks before returning WooCommerce order metadata and the URLs of customer-uploaded attachments, allowing unauthenticated attackers to disclose other customers' order…

  • CVE-2026-14560Sep 11, 2026
    risk 0.00cvss epss

    The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a client-supplied content type and preserving the original filename, allowing unauthenticated attackers to upload arbitrary PHP files and execute code on the…

  • CVE-2026-14559Sep 11, 2026
    risk 0.00cvss epss

    The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, allowing unauthenticated attackers to log in as any registered user, including administrators, by supplying only that user's email address.