CVE-2026-100149: WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons <= 4.7.3 - Unauthenticated Sensitive Information Disclosure via HMAC Signature Collision (Missing Domain Separation) in HMAC Signature Domain-Separation Flaw in `/yamidoo/v1/customer`…
The WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.3 via the 'x-yamidoo-signature (attacker-obtained via inlinejs identify payload)' parameter. This makes it possible for unauthenticated attackers to extract the full customer card — including name, WordPress user ID, order history, order totals, purchased products, payment method labels, and EDD Software Licensing license keys with status and activation counts — for any arbitrary victim email address on the site. Exploitation requires the attacker to register a WooCommerce customer or subscriber-level account with a crafted email address whose local part encodes the target timestamp and victim email, allowing the signature printed into the page HTML by inlinejs() to pass verifyrequest() for an arbitrary victim; both the sharecustomerdata and identifyloggedin settings are enabled by default, so no non-default configuration is required.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker can exploit it, but must first register a WooCommerce customer or subscriber-level account using a crafted email address. No administrative or other privileged WordPress account is required.
Are default plugin settings affected?
Yes. The share_customer_data and identify_logged_in settings are enabled by default, so exploitation does not require a non-default configuration.
What information could be exposed?
An attacker can retrieve the full customer card for an arbitrary victim email address, including the customer name, WordPress user ID, order history and totals, purchased products, payment method labels, and EDD Software Licensing license keys with their status and activation counts.
How does the attacker obtain the signature needed for the request?
The attacker obtains the x-yamidoo-signature from an inline_js identify payload printed in page HTML. A crafted account email local part can cause that signature to validate for an arbitrary victim email address.