CVE-2026-14562: Unknown Teddy-Bear-Customize-Addon

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not perform any authorization or ownership checks before returning WooCommerce order metadata and the URLs of customer-uploaded attachments, allowing unauthenticated attackers to disclose other customers' order and attachment data.

Affected products

  • Unknown Teddy-Bear-Customize-Addon: up to and including 1.0.5

Published 2026-09-11. Last modified 2026-09-11.