PT-2026-104497 · WordPress · Wpzoom Connect

·

CVE-2026-100149

·

Published

2026-10-03

·

Updated

2026-10-03

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons versions prior to 4.7.4
Description Unauthenticated attackers can extract sensitive customer data for any arbitrary email address on a site. This includes the customer name, WordPress user ID, order history, order totals, purchased products, payment method labels, and EDD Software Licensing license keys with status and activation counts. The issue occurs via the x-yamidoo-signature parameter. Exploitation requires the attacker to register a WooCommerce customer or subscriber-level account using a crafted email address that encodes the target timestamp and victim email. This allows the signature generated by the inline js() function to pass the verify request() function for the target victim. The share customer data and identify logged in settings are enabled by default.
Recommendations Update WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons to version 4.7.4 or later. Disable the share customer data and identify logged in settings to mitigate the risk.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100149

Affected Products

Wpzoom Connect