The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.8.2, due to improper CORS handling on the Store API's REST endpoints allowing direct external access from any origin. This can allow unauthenticated attackers to extract sensitive user information including PII(Personal Identifiable Information).
                
            References
                    Configurations
                    No configuration.
History
                    29 Oct 2025, 07:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-10-29 07:15
Updated : 2025-10-30 15:03
NVD link : CVE-2023-7320
Mitre link : CVE-2023-7320
CVE.ORG link : CVE-2023-7320
JSON object : View
Products Affected
                No product.
CWE
                
                    
                        
                        CWE-200
                        
            Exposure of Sensitive Information to an Unauthorized Actor
