CRITICAL
10 CVE-2026-14560 Published 11 Sept 2026
WordPress teddy-bear-customize-addon Arbitrary File Upload
Worried this affects one of your servers?
The teddy-bear-customize-addon WordPress plugin, up to version 1.0.5, has a security flaw that allows unauthenticated attackers to upload arbitrary PHP files.
This is due to the plugin not properly validating uploaded files and relying on client-supplied content types, which can lead to remote code execution on the server.
Reference: CVE-2026-14560 on NVD
← Back to Security News