We have tested CORS headers in the .htaccess file on an empty page, and we don't see any issues on our side.
Header set Access-Control-Allow-Origin "*"
Header set Access-Control-Allow-Methods "GET, POST, OPTIONS, PUT, DELETE"
Header set Access-Control-Allow-Headers "Origin, X-Requested-With, Content-Type, Accept, API-Key, Authorization"
curl -I https://domain.com
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 11 Sep 2023 21:17:03 GMT
Content-Type: text/html;charset=UTF-8
Connection: keep-alive
Access-Control-Allow-Origin: *
Access-Control-Allow-Methods: GET, POST, OPTIONS, PUT, DELETE
Access-Control-Allow-Headers: Origin, X-Requested-With, Content-Type, Accept, API-Key, Authorization
HTNInternalHeaders: Access-Control-Allow-Origin,Access-Control-Allow-Methods,Access-Control-Allow-Header
So, please check your .htaccess file and any settings on your website's side.