Wordpress Alert: Customer data disclosure
An API or plugin returns customer records to an unauthorized caller. Personal and purchase information may be exposed.
What it looks like
An API or plugin returns customer records to an unauthorized caller.
Why it matters
Personal and purchase information may be exposed.
What to check
Review WooCommerce API keys, permissions, and extension endpoints.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WooCommerce REST API overview, WooCommerce security FAQ.
- Categories: WordPress
- Tags: #WordPress Security, #WooCommerce