Wordpress Alert: Customer data disclosure

An API or plugin returns customer records to an unauthorized caller. Personal and purchase information may be exposed.

What it looks like

An API or plugin returns customer records to an unauthorized caller.

Why it matters

Personal and purchase information may be exposed.

What to check

Review WooCommerce API keys, permissions, and extension endpoints.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WooCommerce REST API overview, WooCommerce security FAQ.