Impact
The teddy‑bear‑customize‑addon plugin allows any visitor to upload files without proper validation of the content type and preserves the original filename, enabling the upload of malicious PHP code that can be executed on the server. The weakness corresponds to code injection (CWE‑94), giving attackers the ability to compromise the confidentiality, integrity, and availability of the site.
Affected Systems
The vulnerability affects the WordPress plugin teddy‑bear‑customize‑addon for all installations running version 1.0.5 or older. No other vendor or product versions are listed as affected in the CNA data.
Risk and Exploitability
Because authentication is not required, the plugin’s file upload interface can be exploited without credentials. The vulnerability scores a CVSS score of 10, indicating critical severity. The EPSS score is < 1%, indicating a low but non‑zero probability of exploitation, yet the potential for remote code execution remains high and the vulnerability is not listed in the CISA KEV catalog. An attacker can simply craft a PHP payload, upload it, and then leading to full server compromise.
OpenCVE Enrichment