Search
Find a vulnerability
Search criteria
1 vulnerability found for WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons by wpzoom
CVE-2026-100149 (GCVE-0-2026-100149)
Vulnerability from cvelistv5 – Published: 2026-10-03 05:29 – Updated: 2026-10-03 15:42
VLAI
EPSS
VEX
Title
WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons <= 4.7.3 - Unauthenticated Sensitive Information Disclosure via HMAC Signature Collision (Missing Domain Separation) in HMAC Signature Domain-Separation Flaw in `/yamidoo/v1/customer`…
Summary
The WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.3 via the 'x-yamidoo-signature (attacker-obtained via inline_js identify payload)' parameter. This makes it possible for unauthenticated attackers to extract the full customer card — including name, WordPress user ID, order history, order totals, purchased products, payment method labels, and EDD Software Licensing license keys with status and activation counts — for any arbitrary victim email address on the site. Exploitation requires the attacker to register a WooCommerce customer or subscriber-level account with a crafted email address whose local part encodes the target timestamp and victim email, allowing the signature printed into the page HTML by inline_js() to pass verify_request() for an arbitrary victim; both the share_customer_data and identify_logged_in settings are enabled by default, so no non-default configuration is required.
Severity
5.3 (Medium)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-03 15:26 UTC
CWE
- CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
Assigner
References
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| wpzoom | WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons |
Affected:
0 , ≤ 4.7.3
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100149",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-03T15:26:43.236916Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T15:42:43.954Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "WPZOOM Connect: AI Chat, Click to Chat, Social Icons \u0026 Share Buttons",
"vendor": "wpzoom",
"versions": [
{
"lessThanOrEqual": "4.7.3",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "walid213"
}
],
"descriptions": [
{
"lang": "en",
"value": "The WPZOOM Connect: AI Chat, Click to Chat, Social Icons \u0026 Share Buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.3 via the \u0027x-yamidoo-signature (attacker-obtained via inline_js identify payload)\u0027 parameter. This makes it possible for unauthenticated attackers to extract the full customer card \u2014 including name, WordPress user ID, order history, order totals, purchased products, payment method labels, and EDD Software Licensing license keys with status and activation counts \u2014 for any arbitrary victim email address on the site. Exploitation requires the attacker to register a WooCommerce customer or subscriber-level account with a crafted email address whose local part encodes the target timestamp and victim email, allowing the signature printed into the page HTML by inline_js() to pass verify_request() for an arbitrary victim; both the share_customer_data and identify_logged_in settings are enabled by default, so no non-default configuration is required."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-200",
"description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T05:29:17.935Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e0c9026c-d83e-41ac-be3a-93a33c32c47b?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/social-icons-widget-by-wpzoom/tags/4.7.3/includes/classes/class-wpzoom-ai-chat-customer.php#L82"
},
{
"url": "https://plugins.trac.wordpress.org/browser/social-icons-widget-by-wpzoom/tags/4.7.3/includes/classes/class-wpzoom-ai-chat.php#L921"
},
{
"url": "https://plugins.trac.wordpress.org/browser/social-icons-widget-by-wpzoom/tags/4.7.3/includes/classes/class-wpzoom-ai-chat-customer.php#L93"
},
{
"url": "https://github.com/wpzoom/social-icons-widget-by-wpzoom/commit/351a873ac6c99fd8fb63115628a9d612427c3097"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-25T11:58:05.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-10-02T17:06:00.000Z",
"value": "Disclosed"
}
],
"title": "WPZOOM Connect: AI Chat, Click to Chat, Social Icons \u0026 Share Buttons \u003c= 4.7.3 - Unauthenticated Sensitive Information Disclosure via HMAC Signature Collision (Missing Domain Separation) in HMAC Signature Domain-Separation Flaw in `/yamidoo/v1/customer`\u2026"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-100149",
"datePublished": "2026-10-03T05:29:17.935Z",
"dateReserved": "2026-09-25T11:42:58.288Z",
"dateUpdated": "2026-10-03T15:42:43.954Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}