
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14366 is a Missing Authorization vulnerability in the "Eyewear prescription form" WordPress plugin (by dugudlabs) that allows unauthenticated attackers to create arbitrary WooCommerce products. All versions up to and including 6.0.1 are affected. The vulnerability was published on December 13, 2025, and assigned by Wordfence. It carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-862 (Missing Authorization). Specifically, the SubmitCatProductRequest AJAX action registered by the plugin does not perform any authorization checks, making it accessible to unauthenticated users. An attacker can send a crafted HTTP POST request to the WordPress AJAX endpoint (wp-admin/admin-ajax.php) with the action=SubmitCatProductRequest parameter, supplying arbitrary values for Name, Price, and Parent to create WooCommerce products with attacker-controlled attributes. The vulnerable code is present in admin/class-eyewear_prescription_form-admin.php at lines 71 and 369 of the 6.0.1 release (Wordfence, WordPress Trac).
Successful exploitation allows unauthenticated attackers to inject arbitrary WooCommerce products into the affected store, including setting custom names, prices, and category assignments. This primarily affects data integrity — attackers could flood the product catalog with fraudulent or misleading listings, manipulate pricing, or disrupt store operations. There is no direct confidentiality or availability impact, and lateral movement potential is limited, but the ability to manipulate store inventory without authentication poses a meaningful business risk for e-commerce sites (Wordfence, ENISA EUVD).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.034% (0.000340), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the lack of authentication requirement and low attack complexity make it trivially exploitable by any unauthenticated user if the plugin is installed and active (Wordfence).
/wp-content/plugins/eyewear-prescription-form/).POST /wp-admin/admin-ajax.php.action=SubmitCatProductRequest in the POST body to invoke the unprotected AJAX handler.Name (product name), Price (product price), and Parent (category assignment) in the POST body./wp-admin/admin-ajax.php with action=SubmitCatProductRequest in the request body, originating from unexpected or automated IP addresses.admin-ajax.php with the SubmitCatProductRequest action from unauthenticated sessions (no valid session cookies).Site administrators should update the "Eyewear prescription form" plugin to a version beyond 6.0.1 that includes proper authorization checks on the SubmitCatProductRequest AJAX action. If no patched version is yet available, the recommended workaround is to deactivate and remove the plugin until a fix is released. Additionally, web application firewalls (WAFs) can be configured to block unauthenticated POST requests to admin-ajax.php with the SubmitCatProductRequest action as a temporary measure (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."