Description
The WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.3 via the 'x-yamidoo-signature (attacker-obtained via inline_js identify payload)' parameter. This makes it possible for unauthenticated attackers to extract the full customer card — including name, WordPress user ID, order history, order totals, purchased products, payment method labels, and EDD Software Licensing license keys with status and activation counts — for any arbitrary victim email address on the site. Exploitation requires the attacker to register a WooCommerce customer or subscriber-level account with a crafted email address whose local part encodes the target timestamp and victim email, allowing the signature printed into the page HTML by inline_js() to pass verify_request() for an arbitrary victim; both the share_customer_data and identify_logged_in settings are enabled by default, so no non-default configuration is required.
Published: 2026-10-03
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Disclosure
Action: Patch Plugin
AI Analysis

Impact

The flaw is an HMAC signature domain‑separation weakness that allows an unauthenticated attacker to forge a valid signature. An attacker crafts an email address that encodes the target victim’s timestamp and email, causing the inline_js() function to print a signature that verifies successfully in verify_request(). Once accepted, the plugin returns the full customer card, exposing the victim’s name, WordPress user ID, order history, total amounts, purchased products, payment method labels, and EDD Software Licensing license keys with status and activation counts. This represents a direct disclosure of highly confidential customer data.

Affected Systems

The vulnerability affects the WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons plugin for WordPress in all releases through and including version 4.7.3, when installed on any WordPress site. No other vendors or products are listed.

Risk and Exploitability

The CVSS score of 5.3 classifies the issue as moderate, and there is no EPSS score available. The weakness is not listed in CISA KEV. Exploitation requires no authentication but does require the attacker to register a WooCommerce customer or subscriber account with a crafted email address; this is possible through the site’s default registration flow. Both share_customer_data and identify_logged_in settings are enabled by default, so no special configuration is needed. A successful exploit leads to the full leakage of customer data, which can be leveraged for credential stuffing, phishing, or other downstream attacks. Publicly available exploits have not been reported, but the privacy impact remains severe.

Generated by OpenCVE AI on October 3, 2026 at 06:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the WPZOOM Connect plugin to the latest version released by the vendor that addresses the HMAC domain‑separation issue.
  • If a plugin update cannot be applied immediately, disable the share_customer_data and identify_logged_in settings to stop automatic sharing of customer data via signed requests.
  • Remove or restrict the use of inline_js() signatures in page output to prevent the HMAC value from being exposed and thus forgeable by crafting email addresses.

Generated by OpenCVE AI on October 3, 2026 at 06:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Description The WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.3 via the 'x-yamidoo-signature (attacker-obtained via inline_js identify payload)' parameter. This makes it possible for unauthenticated attackers to extract the full customer card — including name, WordPress user ID, order history, order totals, purchased products, payment method labels, and EDD Software Licensing license keys with status and activation counts — for any arbitrary victim email address on the site. Exploitation requires the attacker to register a WooCommerce customer or subscriber-level account with a crafted email address whose local part encodes the target timestamp and victim email, allowing the signature printed into the page HTML by inline_js() to pass verify_request() for an arbitrary victim; both the share_customer_data and identify_logged_in settings are enabled by default, so no non-default configuration is required.
Title WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons <= 4.7.3 - Unauthenticated Sensitive Information Disclosure via HMAC Signature Collision (Missing Domain Separation) in HMAC Signature Domain-Separation Flaw in `/yamidoo/v1/customer`…
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:43.954Z

Reserved: 2026-09-25T11:42:58.288Z

Link: CVE-2026-100149

cve-icon Vulnrichment

Updated: 2026-10-03T15:39:11.835Z

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:37.370

Modified: 2026-10-03T16:16:30.660

Link: CVE-2026-100149

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T07:00:14Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor