CVE-2026-14562: Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Order Data Disclosure
Published Sep 11, 2026
·Updated
The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not perform any authorization or ownership checks before returning WooCommerce order metadata and the URLs of customer-uploaded attachments, allowing unauthenticated attackers to disclose other customers' order and attachment data.
Affected Software
1 affected component
WordPress teddy-bear-customize-addon<=1.0.5
Event History
Sep 11, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An unauthenticated attacker can exploit it; no login, authorization, or ownership of the targeted order is required.
2
What information may be exposed?
The plugin can return WooCommerce order metadata and URLs for attachments uploaded by customers.
3
Which installations are affected?
The affected plugin is teddy-bear-customize-addon through version 1.0.5. The provided information does not identify any configuration requirement or mitigation other than addressing the affected plugin version.