Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation [zero-bs-crm] <= 6.7.0 (unfixed)
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Automattic Jetpack CRM zero-bs-crm allows PHP Local File Inclusion.This issue affects Jetpack CRM: from n/a through <= 6.7.0.
- Affected:
- up to 6.7.0
- Fix:
- No patched version reported
- Disclosed:
- Feb 20, 2026
CVE-2026-22356 on NVD →
Jetpack CRM <= 6.7.0 - Unauthenticated Local File Inclusion
high
The Jetpack CRM plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.7.0. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls...
- CVSS:
- 8.1
- Affected:
- up to 6.7.0
- Fixed in:
- 6.7.1
- Disclosed:
- Feb 16, 2026
CVE-2026-22356 on NVD →
Jetpackcrm Ext Woo Connect < 2.13 - Sensitive Information Exposure
medium
Multiple plugins for WordPress are vulnerable to Sensitive Information Exposure in various versions via invoices. This makes it possible for unauthenticated attackers to extract sensitive data including from those invoices.
- CVSS:
- 5.3
- Affected:
- up to 4.2.4
- Fixed in:
- 4.2.4
- Disclosed:
- Oct 28, 2024
Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation [zero-bs-crm] < 4.2.4
unknown
Multiple plugins for WordPress are vulnerable to Sensitive Information Exposure in various versions via invoices. This makes it possible for unauthenticated attackers to extract sensitive data including from those invoices.
- Affected:
- up to 4.2.4
- Fixed in:
- 4.2.4
- Disclosed:
- Oct 28, 2024
Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation [zero-bs-crm] < 5.4.0
unknown
[en] The Jetpack CRM plugin for WordPress is vulnerable to PHAR deserialization via the ‘zbscrmcsvimpf’ parameter in the 'zeroBSCRM_CSVImporterLitehtml_app' function in versions up to, and including, 5.3.1. While the function performs a nonce check, steps 2 and 3 of the check do not take any action upon a failed check....
- Affected:
- up to 5.4.0
- Fixed in:
- 5.4.0
- Disclosed:
- Oct 20, 2023
CVE-2022-3342 on NVD →
Jetpack CRM <= 5.5.0 - Authenticated (Client+) Stored Cross-Site Scripting
medium
The Jetpack CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the client phone number field in versions up to, and including, 5.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with client-level access, and above, to inject arbitr...
- CVSS:
- 6.4
- Affected:
- up to 5.5.0
- Fixed in:
- 5.5.1
- Disclosed:
- Sep 12, 2023
Jetpack CRM <= 5.5.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Jetpack CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 5.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator-level access, and above, to inject arbitrary web...
- CVSS:
- 4.4
- Affected:
- up to 5.5.0
- Fixed in:
- 5.5.1
- Disclosed:
- Sep 12, 2023
Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation [zero-bs-crm] < 5.5.1
unknown
The Jetpack CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 5.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator-level access, and above, to inject arbitrary web...
- Affected:
- up to 5.5.1
- Fixed in:
- 5.5.1
- Disclosed:
- Sep 12, 2023
Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation [zero-bs-crm] < 5.5.1
unknown
The Jetpack CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the client phone number field in versions up to, and including, 5.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with client-level access, and above, to inject arbitr...
- Affected:
- up to 5.5.1
- Fixed in:
- 5.5.1
- Disclosed:
- Sep 12, 2023
Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation [zero-bs-crm] < 5.5.0
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Automattic - Jetpack CRM team Jetpack CRM plugin <= 5.4.4 versions.
- Affected:
- up to 5.5.0
- Fixed in:
- 5.5.0
- Disclosed:
- Jun 21, 2023
CVE-2023-27429 on NVD →
Jetpack CRM <= 5.3.1 - Cross-Site Request Forgery and PHAR Deserialization
high
The Jetpack CRM plugin for WordPress is vulnerable to PHAR deserialization via the ‘zbscrmcsvimpf’ parameter in the 'zeroBSCRM_CSVImporterLitehtml_app' function in versions up to, and including, 5.3.1. While the function performs a nonce check, steps 2 and 3 of the check do not take any action upon a failed check. Thes...
- CVSS:
- 7.5
- Affected:
- up to 5.3.1
- Fixed in:
- 5.4.0
- Disclosed:
- Apr 18, 2023
CVE-2022-3342 on NVD →
Jetpack CRM <= 5.4.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Jetpack CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 5.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator-level access, and above, to inject arbitrary web...
- CVSS:
- 4.4
- Affected:
- up to 5.4.4
- Fixed in:
- 5.5.0
- Disclosed:
- Mar 5, 2023
CVE-2023-27429 on NVD →
Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation [zero-bs-crm] < 5.5
unknown
[en] The Jetpack CRM WordPress plugin before 5.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins
- Affected:
- up to 5.5
- Fixed in:
- 5.5
- Disclosed:
- Jan 9, 2023
CVE-2022-4497 on NVD →
Jetpack CRM <= 5.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Jetpack CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and including, 5.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web sc...
- CVSS:
- 6.4
- Affected:
- up to 5.4.4
- Fixed in:
- 5.5
- Disclosed:
- Dec 19, 2022
CVE-2022-4497 on NVD →
Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation [zero-bs-crm] < 5.4.3
unknown
[en] The Jetpack CRM WordPress plugin before 5.4.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- Affected:
- up to 5.4.3
- Fixed in:
- 5.4.3
- Disclosed:
- Dec 12, 2022
CVE-2022-3919 on NVD →
Jetpack CRM <= 5.4.2 - Authenticated (Administrator+) Cross-Site Scripting
medium
The Jetpack CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings in versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arb...
- CVSS:
- 5.5
- Affected:
- up to 5.4.2
- Fixed in:
- 5.4.3
- Disclosed:
- Nov 21, 2022
CVE-2022-3919 on NVD →
Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation [zero-bs-crm] < 5.5.1
unknown
The plugin does not sanitise and escape a client's phone number field, which could allow client users to perform Cross-Site Scripting attacks.
- Affected:
- up to 5.5.1
- Fixed in:
- 5.5.1
Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation [zero-bs-crm] < 5.5.1
unknown
The plugin does not sanitise and escape the tax rate field and custom field placeholders, which could allow CRM Admin users to perform Cross-Site Scripting attacks against site Admins.
- Affected:
- up to 5.5.1
- Fixed in:
- 5.5.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database