CRITICAL 10 CVE-2026-14560 Published 11 Sept 2026

WordPress teddy-bear-customize-addon Arbitrary File Upload

Worried this affects one of your servers?

The teddy-bear-customize-addon WordPress plugin, up to version 1.0.5, has a security flaw that allows unauthenticated attackers to upload arbitrary PHP files.

This is due to the plugin not properly validating uploaded files and relying on client-supplied content types, which can lead to remote code execution on the server.

Reference: CVE-2026-14560 on NVD

← Back to Security News