Sensitive Information Exposure in WPZOOM Connect: AI Chat Plugin for WordPress
CVE-2026-100149

5.3MEDIUM

What is CVE-2026-100149?

The WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons plugin for WordPress is susceptible to a vulnerability that allows unauthenticated attackers to access sensitive customer information. This flaw exists in all versions up to and including 4.7.3, linked to the 'x-yamidoo-signature' parameter. By utilizing a crafted email address to exploit the inline JavaScript payload, attackers can retrieve comprehensive details about victims, such as their names, WordPress user IDs, order histories, payment method labels, and more. This is made possible when specific settings are enabled by default, highlighting the critical need for users to assess their security configurations.

Affected Version(s)

WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons 0 <= 4.7.3

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

walid213
.