SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-14560

CRITICAL · CVSS 10 EPSS 0.44%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The teddy-bear-customize-addon WordPress plugin versions up to 1.0.5 is vulnerable due to improper validation of uploaded files, enabling unauthenticated attackers to upload and execute arbitrary PHP code on the server. This critical vulnerability poses a severe risk to WordPress sites using this plugin, making it imperative for administrators to prioritize immediate patching or removal of the affected plugin to prevent potential exploitation.

CVE
CVE-2026-14560
Severity
CRITICAL
CVSS
10
EPSS
0.44%
WordPress

Original NVD Description

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a client-supplied content type and preserving the original filename, allowing unauthenticated attackers to upload arbitrary PHP files and execute code on the server.