PT-2025-51065 · Automattic+1 · Woocommerce+1

Athiwat Tiprasaharn

+3

·

Published

2025-12-13

·

Updated

2025-12-13

·

CVE-2025-14365

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Eyewear prescription form plugin for WordPress versions up to and including 6.0.1
Description The Eyewear prescription form plugin for WordPress is susceptible to a missing authorization issue. This stems from a lack of proper capability checks on the RemoveItems AJAX action. This allows attackers to delete arbitrary WooCommerce product categories, and their child categories, by manipulating the catIds parameter.
Recommendations Update the Eyewear prescription form plugin to a version beyond 6.0.1.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-14365

Affected Products

Eyewear Prescription Form
Woocommerce