Search

Find a vulnerability

Search criteria

    1 vulnerability found for WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons by wpzoom

    CVE-2026-100149 (GCVE-0-2026-100149)

    Vulnerability from cvelistv5 – Published: 2026-10-03 05:29 – Updated: 2026-10-03 15:42
    VLAI
    Title
    WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons <= 4.7.3 - Unauthenticated Sensitive Information Disclosure via HMAC Signature Collision (Missing Domain Separation) in HMAC Signature Domain-Separation Flaw in `/yamidoo/v1/customer`…
    Summary
    The WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.3 via the 'x-yamidoo-signature (attacker-obtained via inline_js identify payload)' parameter. This makes it possible for unauthenticated attackers to extract the full customer card — including name, WordPress user ID, order history, order totals, purchased products, payment method labels, and EDD Software Licensing license keys with status and activation counts — for any arbitrary victim email address on the site. Exploitation requires the attacker to register a WooCommerce customer or subscriber-level account with a crafted email address whose local part encodes the target timestamp and victim email, allowing the signature printed into the page HTML by inline_js() to pass verify_request() for an arbitrary victim; both the share_customer_data and identify_logged_in settings are enabled by default, so no non-default configuration is required.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:26 UTC
    CWE
    • CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
    Impacted products
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-100149",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:26:43.236916Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:43.954Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WPZOOM Connect: AI Chat, Click to Chat, Social Icons \u0026 Share Buttons",
              "vendor": "wpzoom",
              "versions": [
                {
                  "lessThanOrEqual": "4.7.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "walid213"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The WPZOOM Connect: AI Chat, Click to Chat, Social Icons \u0026 Share Buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.3 via the \u0027x-yamidoo-signature (attacker-obtained via inline_js identify payload)\u0027 parameter. This makes it possible for unauthenticated attackers to extract the full customer card \u2014 including name, WordPress user ID, order history, order totals, purchased products, payment method labels, and EDD Software Licensing license keys with status and activation counts \u2014 for any arbitrary victim email address on the site. Exploitation requires the attacker to register a WooCommerce customer or subscriber-level account with a crafted email address whose local part encodes the target timestamp and victim email, allowing the signature printed into the page HTML by inline_js() to pass verify_request() for an arbitrary victim; both the share_customer_data and identify_logged_in settings are enabled by default, so no non-default configuration is required."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T05:29:17.935Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e0c9026c-d83e-41ac-be3a-93a33c32c47b?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/social-icons-widget-by-wpzoom/tags/4.7.3/includes/classes/class-wpzoom-ai-chat-customer.php#L82"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/social-icons-widget-by-wpzoom/tags/4.7.3/includes/classes/class-wpzoom-ai-chat.php#L921"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/social-icons-widget-by-wpzoom/tags/4.7.3/includes/classes/class-wpzoom-ai-chat-customer.php#L93"
            },
            {
              "url": "https://github.com/wpzoom/social-icons-widget-by-wpzoom/commit/351a873ac6c99fd8fb63115628a9d612427c3097"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-25T11:58:05.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T17:06:00.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "WPZOOM Connect: AI Chat, Click to Chat, Social Icons \u0026 Share Buttons \u003c= 4.7.3 - Unauthenticated Sensitive Information Disclosure via HMAC Signature Collision (Missing Domain Separation) in HMAC Signature Domain-Separation Flaw in `/yamidoo/v1/customer`\u2026"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-100149",
        "datePublished": "2026-10-03T05:29:17.935Z",
        "dateReserved": "2026-09-25T11:42:58.288Z",
        "dateUpdated": "2026-10-03T15:42:43.954Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }