Eyewear prescription form [eyewear-prescription-form] <= 6.0.1 (unfixed)
unknown
[en] The Eyewear prescription form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.0.1. This is due to missing authorization checks on the SubmitCatProductRequest AJAX action. This makes it possible for unauthenticated attackers to create arbitrary WooCommerce product...
- Affected:
- up to 6.0.1
- Fix:
- No patched version reported
- Disclosed:
- Dec 13, 2025
CVE-2025-14366 on NVD →
Eyewear prescription form [eyewear-prescription-form] <= 6.0.1 (unfixed)
unknown
[en] The Eyewear prescription form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.0.1. This is due to missing capability checks on the RemoveItems AJAX action. This makes it possible for unauthenticated attackers to delete arbitrary WooCommerce product categories, in...
- Affected:
- up to 6.0.1
- Fix:
- No patched version reported
- Disclosed:
- Dec 13, 2025
CVE-2025-14365 on NVD →
Eyewear prescription form <= 7.0.2 - Missing Authorization to Unauthenticated Arbitrary WooCommerce Category Deletion
medium
The Eyewear prescription form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 7.0.2. This is due to missing capability checks on the RemoveItems AJAX action. This makes it possible for unauthenticated attackers to delete arbitrary WooCommerce product categories, includi...
- CVSS:
- 5.3
- Affected:
- up to 7.0.2
- Fixed in:
- 7.0.3
- Disclosed:
- Dec 12, 2025
CVE-2025-14365 on NVD →
Eyewear prescription form <= 7.0.2 - Missing Authorization to Unauthenticated Arbitrary WooCommerce Product Creation
medium
The Eyewear prescription form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 7.0.2. This is due to missing authorization checks on the SubmitCatProductRequest AJAX action. This makes it possible for unauthenticated attackers to create arbitrary WooCommerce products wit...
- CVSS:
- 5.3
- Affected:
- up to 7.0.2
- Fixed in:
- 7.0.3
- Disclosed:
- Dec 12, 2025
CVE-2025-14366 on NVD →
Eyewear prescription form [eyewear-prescription-form] < 4.0.19
unknown
[en] Missing Authorization vulnerability in dugudlabs Eyewear prescription form allows Privilege Escalation.This issue affects Eyewear prescription form: from n/a through 4.0.18.
- Affected:
- up to 4.0.19
- Fixed in:
- 4.0.19
- Disclosed:
- Dec 13, 2024
CVE-2024-54239 on NVD →
Eyewear prescription form <= 4.0.18 - Missing Authorization to Unauthenticated Arbitrary Options Update
critical
The Eyewear prescription form plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the adminSetting() function in all versions up to, and including, 4.0.18. This makes it possible for unauthenticated attackers to update arbitr...
- CVSS:
- 9.8
- Affected:
- up to 4.0.18
- Fixed in:
- 4.0.19
- Disclosed:
- Dec 6, 2024
CVE-2024-54239 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database