plugin

Eyewear Prescription Form Vulnerabilities

6 known security issues reported for the Eyewear Prescription Form WordPress plugin. Most recent disclosed Dec 13, 2025.

1 critical 2 medium

Running Eyewear Prescription Form on your site? Check whether your installed version is affected.

Scan your site free

Eyewear prescription form [eyewear-prescription-form] <= 6.0.1 (unfixed)

unknown

[en] The Eyewear prescription form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.0.1. This is due to missing authorization checks on the SubmitCatProductRequest AJAX action. This makes it possible for unauthenticated attackers to create arbitrary WooCommerce product...

Affected:
up to 6.0.1
Fix:
No patched version reported
Disclosed:
Dec 13, 2025

CVE-2025-14366 on NVD →

Eyewear prescription form [eyewear-prescription-form] <= 6.0.1 (unfixed)

unknown

[en] The Eyewear prescription form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.0.1. This is due to missing capability checks on the RemoveItems AJAX action. This makes it possible for unauthenticated attackers to delete arbitrary WooCommerce product categories, in...

Affected:
up to 6.0.1
Fix:
No patched version reported
Disclosed:
Dec 13, 2025

CVE-2025-14365 on NVD →

Eyewear prescription form <= 7.0.2 - Missing Authorization to Unauthenticated Arbitrary WooCommerce Category Deletion

medium

The Eyewear prescription form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 7.0.2. This is due to missing capability checks on the RemoveItems AJAX action. This makes it possible for unauthenticated attackers to delete arbitrary WooCommerce product categories, includi...

CVSS:
5.3
Affected:
up to 7.0.2
Fixed in:
7.0.3
Disclosed:
Dec 12, 2025

CVE-2025-14365 on NVD →

Eyewear prescription form <= 7.0.2 - Missing Authorization to Unauthenticated Arbitrary WooCommerce Product Creation

medium

The Eyewear prescription form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 7.0.2. This is due to missing authorization checks on the SubmitCatProductRequest AJAX action. This makes it possible for unauthenticated attackers to create arbitrary WooCommerce products wit...

CVSS:
5.3
Affected:
up to 7.0.2
Fixed in:
7.0.3
Disclosed:
Dec 12, 2025

CVE-2025-14366 on NVD →

Eyewear prescription form [eyewear-prescription-form] < 4.0.19

unknown

[en] Missing Authorization vulnerability in dugudlabs Eyewear prescription form allows Privilege Escalation.This issue affects Eyewear prescription form: from n/a through 4.0.18.

Affected:
up to 4.0.19
Fixed in:
4.0.19
Disclosed:
Dec 13, 2024

CVE-2024-54239 on NVD →

Eyewear prescription form <= 4.0.18 - Missing Authorization to Unauthenticated Arbitrary Options Update

critical

The Eyewear prescription form plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the adminSetting() function in all versions up to, and including, 4.0.18. This makes it possible for unauthenticated attackers to update arbitr...

CVSS:
9.8
Affected:
up to 4.0.18
Fixed in:
4.0.19
Disclosed:
Dec 6, 2024

CVE-2024-54239 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database