CVE-2023-7320: WooCommerce <= 7.8.2 - Sensitive Information Exposure
The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.8.2, due to improper CORS handling on the Store API's REST endpoints allowing direct external access from any origin. This can allow unauthenticated attackers to extract sensitive user information including PII(Personal Identifiable Information).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7320?
CVE-2023-7320 has a severity rating of high due to its potential for exposing sensitive information.
How do I fix CVE-2023-7320?
To fix CVE-2023-7320, update your WooCommerce plugin to version 7.8.3 or higher.
What type of vulnerability is CVE-2023-7320?
CVE-2023-7320 is categorized as a Sensitive Information Exposure vulnerability.
Who is affected by CVE-2023-7320?
CVE-2023-7320 affects all versions of the WooCommerce plugin for WordPress up to and including 7.8.2.
What can attackers do with CVE-2023-7320?
Attackers can exploit CVE-2023-7320 to access sensitive information due to improper CORS handling.