天下漏洞,尽知其名
MEDIUM 重点关注

CVE-2026-100149 WPZOOM Connect 敏感信息泄露漏洞

影响未授权攻击者可获取任意客户的订单、支付及许可证密钥等敏感信息

AI 研判

WordPress 插件 WPZOOM Connect(AI Chat、Click to Chat、Social Icons & Share Buttons)在 4.7.3 及之前所有版本中存在敏感信息泄露漏洞。攻击者可通过构造特定邮箱注册账户,利用页面中内联脚本生成的签名绕过校验,从而读取任意受害者的完整客户资料。

影响范围

WPZOOM Connect

影响 WPZOOM Connect 插件所有版本至 4.7.3(含)。更高版本是否修复暂无公开信息。

漏洞详情

漏洞属于敏感信息暴露,成因是插件通过 inline_js() 将签名写入页面 HTML,而 verify_request() 的校验逻辑可被绕过。攻击者注册一个本地部分编码了目标时间戳与受害者邮箱的 WooCommerce 客户或订阅者账户,即可让签名通过校验。由于 share_customer_data 与 identify_logged_in 默认开启,无需特殊配置即可利用,从而提取姓名、用户 ID、订单历史、订单金额、购买商品、支付方式标签以及 EDD 软件许可密钥及状态和激活次数。

利用条件与风险

利用前提是攻击者能注册一个邮箱经过构造的账户,且目标站点使用默认配置。实战中可批量枚举邮箱窃取客户隐私与许可证密钥,风险较高。

修复建议

建议升级至官方修复版本(暂无公开信息确认具体版本),或临时禁用 share_customer_data 与 identify_logged_in 设置,并限制账户注册与相关接口访问。

原始情报

The WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.3 via the ‘x-yamidoo-signature (attacker-obtained via inline_js identify payload)’ parameter. This makes it possible for unauthenticated attackers to extract the full customer card — including name, WordPress user ID, order history, order totals, purchased products, payment method labels, and EDD Software Licensing license keys with status and activation counts — for any arbitrary victim email address on the site. Exploitation requires the attacker to register a WooCommerce customer or subscriber-level account with a crafted email address whose local part encodes the target timestamp and victim email, allowing the signature printed into the page HTML by inline_js() to pass verify_request() for an arbitrary victim; both the share_customer_data and identify_logged_in settings are enabled by default, so no non-default configuration is required.