CVE-2025-14365

T

he Eyewear prescription form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.0.1. This is due to missing capability checks on the RemoveItems AJAX action. This makes it possible for unauthenticated attackers to delete arbitrary WooCommerce product categories, including all of their child categories, via the 'catIds' parameter.

Configurations

No configuration.

History

15 Dec 2025, 18:22

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-13 16:16

Updated : 2025-12-15 18:22


NVD link : CVE-2025-14365

Mitre link : CVE-2025-14365

CVE.ORG link : CVE-2025-14365


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization