WooCommerce
cpe:2.3:a:woocommerce:woocommerce:*:*:*:*:wordpress:*:*
- <= 7.8.2
A vulnerability allowing sensitive information exposure exists in the WooCommerce plugin for WordPress, in versions through 7.8.2. This issue arises from improper Cross-Origin Resource Sharing (CORS) management on the Store API's REST endpoints, which permits direct external access from any origin. As a result, unauthenticated attackers could potentially access and extract sensitive user information, including personal identifiable information (PII).
Exploitation of this vulnerability could lead to unauthorized access to sensitive user information, including PII.
Users are advised to update WooCommerce to version 7.9.0 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.