CVE-2026-100149: WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons <= 4.7.3 - Unauthenticated Sensitive Information Disclosure via HMAC Signature Collision (Missing Domain Separation) in HMAC Signature Domain-Separation Flaw in `/yamidoo/v1/customer`…

Published Oct 3, 2026
·
Updated

The WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.3 via the 'x-yamidoo-signature (attacker-obtained via inlinejs identify payload)' parameter. This makes it possible for unauthenticated attackers to extract the full customer card — including name, WordPress user ID, order history, order totals, purchased products, payment method labels, and EDD Software Licensing license keys with status and activation counts — for any arbitrary victim email address on the site. Exploitation requires the attacker to register a WooCommerce customer or subscriber-level account with a crafted email address whose local part encodes the target timestamp and victim email, allowing the signature printed into the page HTML by inlinejs() to pass verifyrequest() for an arbitrary victim; both the sharecustomerdata and identifyloggedin settings are enabled by default, so no non-default configuration is required.

Affected Software

1 affected component
WPZOOM WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons<=4.7.3

Event History

Oct 3, 2026
CVE Published
via MITRE·05:29 AM
Data Sourced
via MITRE·05:29 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An unauthenticated attacker can exploit it, but must first register a WooCommerce customer or subscriber-level account using a crafted email address. No administrative or other privileged WordPress account is required.

2

Are default plugin settings affected?

Yes. The share_customer_data and identify_logged_in settings are enabled by default, so exploitation does not require a non-default configuration.

3

What information could be exposed?

An attacker can retrieve the full customer card for an arbitrary victim email address, including the customer name, WordPress user ID, order history and totals, purchased products, payment method labels, and EDD Software Licensing license keys with their status and activation counts.

4

How does the attacker obtain the signature needed for the request?

The attacker obtains the x-yamidoo-signature from an inline_js identify payload printed in page HTML. A crafted account email local part can cause that signature to validate for an arbitrary victim email address.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203