Impact
The teddy‑bear‑customize‑addon WordPress plugin, through version 1.0.5, fails to perform authentication or ownership checks before returning WooCommerce order metadata and URLs linking to customer-uploaded attachments. This flaw allows an unauthenticated user to retrieve other customers' order details and attachment links, resulting in the disclosure of sensitive user information without any special privileges.
Affected Systems
The vulnerability affects installations of the WordPress toy custom-design plugin named teddy-bear-customize-addon, specifically versions 1.0.5 and earlier. Any WordPress site that has this plugin installed and has WooCommerce order data is at risk, regardless of other configuration.
Risk and Exploitability
Based on the description, it is inferred that an attacker can trigger the vulnerability by sending a simple HTTP request to the plugin’s endpoint that returns order data. The flaw permits reading other customers’ order data without any authentication. The CVSS score of 5.3 indicates moderate severity, and the EPSS score of < 1% indicates a very low but non‑zero exploitation probability; the issue is not catalogued in CISA KEV. No special privileges or additional exploits are required beyond the standard HTTP request.
OpenCVE Enrichment