Impact
The flaw is an HMAC signature domain‑separation weakness that allows an unauthenticated attacker to forge a valid signature. An attacker crafts an email address that encodes the target victim’s timestamp and email, causing the inline_js() function to print a signature that verifies successfully in verify_request(). Once accepted, the plugin returns the full customer card, exposing the victim’s name, WordPress user ID, order history, total amounts, purchased products, payment method labels, and EDD Software Licensing license keys with status and activation counts. This represents a direct disclosure of highly confidential customer data.
Affected Systems
The vulnerability affects the WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons plugin for WordPress in all releases through and including version 4.7.3, when installed on any WordPress site. No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 5.3 classifies the issue as moderate, and there is no EPSS score available. The weakness is not listed in CISA KEV. Exploitation requires no authentication but does require the attacker to register a WooCommerce customer or subscriber account with a crafted email address; this is possible through the site’s default registration flow. Both share_customer_data and identify_logged_in settings are enabled by default, so no special configuration is needed. A successful exploit leads to the full leakage of customer data, which can be leveraged for credential stuffing, phishing, or other downstream attacks. Publicly available exploits have not been reported, but the privacy impact remains severe.
OpenCVE Enrichment