VYPR

Eyewear Prescription Form

by WordPress

Source repositories

CVEs (3)

  • CVE-2024-54239CriDec 13, 2024
    risk 0.64cvss 9.8epss 0.03

    Missing Authorization vulnerability in dugudlabs Eyewear prescription form eyewear-prescription-form allows Privilege Escalation.This issue affects Eyewear prescription form: from n/a through <= 4.0.18.

  • CVE-2025-14366MedDec 13, 2025
    risk 0.34cvss 5.3epss 0.00

    The Eyewear prescription form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.0.1. This is due to missing authorization checks on the SubmitCatProductRequest AJAX action. This makes it possible for unauthenticated attackers to create arbitrary WooCommerce products with custom names, prices, and category assignments via the 'Name', 'Price', and 'Parent' parameters.

  • CVE-2025-14365MedDec 13, 2025
    risk 0.34cvss 5.3epss 0.00

    The Eyewear prescription form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.0.1. This is due to missing capability checks on the RemoveItems AJAX action. This makes it possible for unauthenticated attackers to delete arbitrary WooCommerce product categories, including all of their child categories, via the 'catIds' parameter.