CVE-2023-7320 Details
Description
The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.8.2, due to improper CORS handling on the Store API's REST endpoints allowing direct external access from any origin. This can allow unauthenticated attackers to extract sensitive user information including PII(Personal Identifiable Information).
A vulnerability allowing sensitive information exposure exists in the WooCommerce plugin for WordPress, in versions through 7.8.2. This issue arises from improper Cross-Origin Resource Sharing (CORS) management on the Store API's REST endpoints, which permits direct external access from any origin. As a result, unauthenticated attackers could potentially access and extract sensitive user information, including personal identifiable information (PII).
Users are advised to update WooCommerce to version 7.9.0 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 29, 2025CISA-ADP
Assessed Oct 29, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| WooCommerce | <= 7.8.2 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 29, 2025 | New CVE Received | [email protected] |
Volerion