WordPress · Wpzoom Connect · CVE-2026-100149
**Name of the Vulnerable Software and Affected Versions**
WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons versions prior to 4.7.4
**Description**
Unauthenticated attackers can extract sensitive customer data for any arbitrary email address on a site. This includes the customer name, WordPress user ID, order history, order totals, purchased products, payment method labels, and EDD Software Licensing license keys with status and activation counts. The issue occurs via the `x-yamidoo-signature` parameter. Exploitation requires the attacker to register a WooCommerce customer or subscriber-level account using a crafted email address that encodes the target timestamp and victim email. This allows the signature generated by the `inline js()` function to pass the `verify request()` function for the target victim. The `share customer data` and `identify logged in` settings are enabled by default.
**Recommendations**
Update WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons to version 4.7.4 or later.
Disable the `share customer data` and `identify logged in` settings to mitigate the risk.