Description
The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not perform any authorization or ownership checks before returning WooCommerce order metadata and the URLs of customer-uploaded attachments, allowing unauthenticated attackers to disclose other customers' order and attachment data.
Published: 2026-09-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The teddy‑bear‑customize‑addon WordPress plugin, through version 1.0.5, fails to perform authentication or ownership checks before returning WooCommerce order metadata and URLs linking to customer-uploaded attachments. This flaw allows an unauthenticated user to retrieve other customers' order details and attachment links, resulting in the disclosure of sensitive user information without any special privileges.

Affected Systems

The vulnerability affects installations of the WordPress toy custom-design plugin named teddy-bear-customize-addon, specifically versions 1.0.5 and earlier. Any WordPress site that has this plugin installed and has WooCommerce order data is at risk, regardless of other configuration.

Risk and Exploitability

Based on the description, it is inferred that an attacker can trigger the vulnerability by sending a simple HTTP request to the plugin’s endpoint that returns order data. The flaw permits reading other customers’ order data without any authentication. The CVSS score of 5.3 indicates moderate severity, and the EPSS score of < 1% indicates a very low but non‑zero exploitation probability; the issue is not catalogued in CISA KEV. No special privileges or additional exploits are required beyond the standard HTTP request.

Generated by OpenCVE AI on September 11, 2026 at 15:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the teddy-bear-customize-addon plugin to the latest available version to include proper authorization checks.
  • If no patched version is available, remove or deactivate the plugin from the WordPress installation.
  • While a fix is pending, restrict access to the order‑metadata endpoint by implementing a custom authentication check or using server‑side access controls such as .htaccess restrictions.

Generated by OpenCVE AI on September 11, 2026 at 15:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 11 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not perform any authorization or ownership checks before returning WooCommerce order metadata and the URLs of customer-uploaded attachments, allowing unauthenticated attackers to disclose other customers' order and attachment data.
Title Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Order Data Disclosure
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-11T10:10:47.911Z

Reserved: 2026-07-03T09:48:40.298Z

Link: CVE-2026-14562

cve-icon Vulnrichment

Updated: 2026-09-11T10:02:56.624Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T07:16:46.080

Modified: 2026-09-11T17:35:21.440

Link: CVE-2026-14562

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T15:45:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor