---
id: CVE-2025-14365
title: >-
  The Eyewear prescription form plugin for WordPress is vulnerable to Missing
  Authorization in all versions up to, and including, 6.0.1
summary: >-
  The Eyewear prescription form plugin for WordPress is vulnerable to Missing
  Authorization in all versions up to, and including, 6.0.1. This is due to
  missing capability checks on the RemoveItems AJAX action. This makes it
  possible for un…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
published: '2025-12-13'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14365'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/eyewear-prescription-form/tags/6.0.1/admin/class-eyewear_prescription_form-admin.php#L326
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/eyewear-prescription-form/tags/6.0.1/admin/class-eyewear_prescription_form-admin.php#L74
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/b85fc103-20e5-4599-8ed5-5bd5d9c447ee?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.0027
epssPercentile: 0.17498
ingestedAt: '2026-10-07T20:46:46.929Z'
---

## Overview

The Eyewear prescription form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.0.1. This is due to missing capability checks on the RemoveItems AJAX action. This makes it possible for unauthenticated attackers to delete arbitrary WooCommerce product categories, including all of their child categories, via the 'catIds' parameter.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
