PT-2026-104497 · WordPress · Wpzoom Connect
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons versions prior to 4.7.4
Description
Unauthenticated attackers can extract sensitive customer data for any arbitrary email address on a site. This includes the customer name, WordPress user ID, order history, order totals, purchased products, payment method labels, and EDD Software Licensing license keys with status and activation counts. The issue occurs via the
x-yamidoo-signature parameter. Exploitation requires the attacker to register a WooCommerce customer or subscriber-level account using a crafted email address that encodes the target timestamp and victim email. This allows the signature generated by the inline js() function to pass the verify request() function for the target victim. The share customer data and identify logged in settings are enabled by default.Recommendations
Update WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons to version 4.7.4 or later.
Disable the
share customer data and identify logged in settings to mitigate the risk.Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wpzoom Connect