CVE-2026-100149
Received Received - Intake

Sensitive Information Exposure in WPZOOM Connect WordPress Plugin

Vulnerability report for CVE-2026-100149, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: Wordfence

Description

The WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.3 via the 'x-yamidoo-signature (attacker-obtained via inline_js identify payload)' parameter. This makes it possible for unauthenticated attackers to extract the full customer card β€” including name, WordPress user ID, order history, order totals, purchased products, payment method labels, and EDD Software Licensing license keys with status and activation counts β€” for any arbitrary victim email address on the site. Exploitation requires the attacker to register a WooCommerce customer or subscriber-level account with a crafted email address whose local part encodes the target timestamp and victim email, allowing the signature printed into the page HTML by inline_js() to pass verify_request() for an arbitrary victim; both the share_customer_data and identify_logged_in settings are enabled by default, so no non-default configuration is required.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
wpzoom ai_chat to 4.7.3 (inc)
wpzoom social_icons_widget *
wpzoom connect_ai_chat to 4.7.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the WPZOOM Connect plugin for WordPress allows unauthenticated attackers to expose sensitive customer data by exploiting a parameter called 'x-yamidoo-signature'. The flaw exists in versions up to 4.7.3 and enables attackers to retrieve full customer details such as names, order history, payment methods, and license keys by crafting a specific email address during registration.

Detection Guidance

This vulnerability involves sensitive information exposure in the WPZOOM Connect plugin. To detect it, check if the plugin is installed and review versions up to 4.7.3. Look for unauthorized access to customer data via the 'x-yamidoo-signature' parameter in requests. Monitor for suspicious requests encoding victim email addresses in crafted accounts.

Impact Analysis

If you use this plugin, attackers could steal customer data including names, order history, payment methods, and license keys. This could lead to privacy breaches, financial fraud, or misuse of customer information. The attack requires minimal effort as it exploits default settings and does not need complex technical skills.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA due to unauthorized exposure of personal and financial data. GDPR requires protecting personal data, and HIPAA mandates safeguarding health-related information. A breach could result in legal penalties, fines, and reputational damage for organizations handling such data.

Mitigation Strategies

Immediately update the WPZOOM Connect plugin to the latest version beyond 4.7.3. Disable the 'share_customer_data' and 'identify_logged_in' settings if they are enabled. Review all customer data exposed and revoke any compromised license keys or payment methods.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100149. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart