CVE-2025-14366: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14366 is a Missing Authorization vulnerability in the "Eyewear prescription form" WordPress plugin (by dugudlabs) that allows unauthenticated attackers to create arbitrary WooCommerce products. All versions up to and including 6.0.1 are affected. The vulnerability was published on December 13, 2025, and assigned by Wordfence. It carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-862 (Missing Authorization). Specifically, the SubmitCatProductRequest AJAX action registered by the plugin does not perform any authorization checks, making it accessible to unauthenticated users. An attacker can send a crafted HTTP POST request to the WordPress AJAX endpoint (wp-admin/admin-ajax.php) with the action=SubmitCatProductRequest parameter, supplying arbitrary values for Name, Price, and Parent to create WooCommerce products with attacker-controlled attributes. The vulnerable code is present in admin/class-eyewear_prescription_form-admin.php at lines 71 and 369 of the 6.0.1 release (Wordfence, WordPress Trac).

Impact

Successful exploitation allows unauthenticated attackers to inject arbitrary WooCommerce products into the affected store, including setting custom names, prices, and category assignments. This primarily affects data integrity — attackers could flood the product catalog with fraudulent or misleading listings, manipulate pricing, or disrupt store operations. There is no direct confidentiality or availability impact, and lateral movement potential is limited, but the ability to manipulate store inventory without authentication poses a meaningful business risk for e-commerce sites (Wordfence, ENISA EUVD).

Exploitability

No public proof-of-concept exploit code or active in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.034% (0.000340), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the lack of authentication requirement and low attack complexity make it trivially exploitable by any unauthenticated user if the plugin is installed and active (Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the "Eyewear prescription form" plugin (version ≤ 6.0.1) with WooCommerce active, using tools like WPScan or by checking publicly accessible plugin files (e.g., /wp-content/plugins/eyewear-prescription-form/).
  2. Craft the AJAX request: Prepare an HTTP POST request targeting the WordPress AJAX endpoint: POST /wp-admin/admin-ajax.php.
  3. Set the action parameter: Include action=SubmitCatProductRequest in the POST body to invoke the unprotected AJAX handler.
  4. Supply malicious product data: Add arbitrary values for Name (product name), Price (product price), and Parent (category assignment) in the POST body.
  5. Submit the request: Send the unauthenticated request — no cookies, nonce, or credentials are required. The plugin will create the specified WooCommerce product directly in the store's database (Wordfence, WordPress Trac).

Indicators of compromise

  • Network: Unusual unauthenticated POST requests to /wp-admin/admin-ajax.php with action=SubmitCatProductRequest in the request body, originating from unexpected or automated IP addresses.
  • Logs: WordPress/web server access logs showing repeated POST requests to admin-ajax.php with the SubmitCatProductRequest action from unauthenticated sessions (no valid session cookies).
  • Database/Application: Unexpected WooCommerce products appearing in the store catalog with unusual names, prices (e.g., $0 or extremely high values), or category assignments not created by legitimate administrators.

Mitigation and workarounds

Site administrators should update the "Eyewear prescription form" plugin to a version beyond 6.0.1 that includes proper authorization checks on the SubmitCatProductRequest AJAX action. If no patched version is yet available, the recommended workaround is to deactivate and remove the plugin until a fix is released. Additionally, web application firewalls (WAFs) can be configured to block unauthenticated POST requests to admin-ajax.php with the SubmitCatProductRequest action as a temporary measure (Wordfence).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management