---
id: CVE-2025-14366
title: >-
  The Eyewear prescription form plugin for WordPress is vulnerable to Missing
  Authorization in all versions up to, and including, 6.0.1
summary: >-
  The Eyewear prescription form plugin for WordPress is vulnerable to Missing
  Authorization in all versions up to, and including, 6.0.1. This is due to
  missing authorization checks on the SubmitCatProductRequest AJAX action. This
  makes it …
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
published: '2025-12-13'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14366'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/eyewear-prescription-form/tags/6.0.1/admin/class-eyewear_prescription_form-admin.php#L369
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/eyewear-prescription-form/tags/6.0.1/admin/class-eyewear_prescription_form-admin.php#L71
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/0f21d7a2-3b4f-487f-a64a-b963427233b3?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.0027
epssPercentile: 0.175
ingestedAt: '2026-10-07T20:46:46.930Z'
---

## Overview

The Eyewear prescription form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.0.1. This is due to missing authorization checks on the SubmitCatProductRequest AJAX action. This makes it possible for unauthenticated attackers to create arbitrary WooCommerce products with custom names, prices, and category assignments via the 'Name', 'Price', and 'Parent' parameters.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
