The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a client-supplied content type and preserving the original filename, allowing unauthenticated attackers to upload arbitrary PHP files and execute code on the server.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-11 07:16
Updated : 2026-09-11 17:35
NVD link : CVE-2026-14560
Mitre link : CVE-2026-14560
CVE.ORG link : CVE-2026-14560
JSON object : View
Products Affected
No product.
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
