plugin

Zero Bs Crm Vulnerabilities

18 known security issues reported for the Zero Bs Crm WordPress plugin. Most recent disclosed Feb 20, 2026.

2 high 6 medium

Running Zero Bs Crm on your site? Check whether your installed version is affected.

Scan your site free

Jetpack CRM &#8211; Clients, Leads, Invoices, Billing, Email Marketing, &amp; Automation [zero-bs-crm] <= 6.7.0 (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Automattic Jetpack CRM zero-bs-crm allows PHP Local File Inclusion.This issue affects Jetpack CRM: from n/a through <= 6.7.0.

Affected:
up to 6.7.0
Fix:
No patched version reported
Disclosed:
Feb 20, 2026

CVE-2026-22356 on NVD →

Jetpack CRM <= 6.7.0 - Unauthenticated Local File Inclusion

high

The Jetpack CRM plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.7.0. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls...

CVSS:
8.1
Affected:
up to 6.7.0
Fixed in:
6.7.1
Disclosed:
Feb 16, 2026

CVE-2026-22356 on NVD →

Jetpackcrm Ext Woo Connect < 2.13 - Sensitive Information Exposure

medium

Multiple plugins for WordPress are vulnerable to Sensitive Information Exposure in various versions via invoices. This makes it possible for unauthenticated attackers to extract sensitive data including from those invoices.

CVSS:
5.3
Affected:
up to 4.2.4
Fixed in:
4.2.4
Disclosed:
Oct 28, 2024

Jetpack CRM &#8211; Clients, Leads, Invoices, Billing, Email Marketing, &amp; Automation [zero-bs-crm] < 4.2.4

unknown

Multiple plugins for WordPress are vulnerable to Sensitive Information Exposure in various versions via invoices. This makes it possible for unauthenticated attackers to extract sensitive data including from those invoices.

Affected:
up to 4.2.4
Fixed in:
4.2.4
Disclosed:
Oct 28, 2024

Jetpack CRM &#8211; Clients, Leads, Invoices, Billing, Email Marketing, &amp; Automation [zero-bs-crm] < 5.4.0

unknown

[en] The Jetpack CRM plugin for WordPress is vulnerable to PHAR deserialization via the ‘zbscrmcsvimpf’ parameter in the 'zeroBSCRM_CSVImporterLitehtml_app' function in versions up to, and including, 5.3.1. While the function performs a nonce check, steps 2 and 3 of the check do not take any action upon a failed check....

Affected:
up to 5.4.0
Fixed in:
5.4.0
Disclosed:
Oct 20, 2023

CVE-2022-3342 on NVD →

Jetpack CRM <= 5.5.0 - Authenticated (Client+) Stored Cross-Site Scripting

medium

The Jetpack CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the client phone number field in versions up to, and including, 5.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with client-level access, and above, to inject arbitr...

CVSS:
6.4
Affected:
up to 5.5.0
Fixed in:
5.5.1
Disclosed:
Sep 12, 2023

Jetpack CRM <= 5.5.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Jetpack CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 5.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator-level access, and above, to inject arbitrary web...

CVSS:
4.4
Affected:
up to 5.5.0
Fixed in:
5.5.1
Disclosed:
Sep 12, 2023

Jetpack CRM &#8211; Clients, Leads, Invoices, Billing, Email Marketing, &amp; Automation [zero-bs-crm] < 5.5.1

unknown

The Jetpack CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 5.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator-level access, and above, to inject arbitrary web...

Affected:
up to 5.5.1
Fixed in:
5.5.1
Disclosed:
Sep 12, 2023

Jetpack CRM &#8211; Clients, Leads, Invoices, Billing, Email Marketing, &amp; Automation [zero-bs-crm] < 5.5.1

unknown

The Jetpack CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the client phone number field in versions up to, and including, 5.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with client-level access, and above, to inject arbitr...

Affected:
up to 5.5.1
Fixed in:
5.5.1
Disclosed:
Sep 12, 2023

Jetpack CRM &#8211; Clients, Leads, Invoices, Billing, Email Marketing, &amp; Automation [zero-bs-crm] < 5.5.0

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Automattic - Jetpack CRM team Jetpack CRM plugin <= 5.4.4 versions.

Affected:
up to 5.5.0
Fixed in:
5.5.0
Disclosed:
Jun 21, 2023

CVE-2023-27429 on NVD →

Jetpack CRM <= 5.3.1 - Cross-Site Request Forgery and PHAR Deserialization

high

The Jetpack CRM plugin for WordPress is vulnerable to PHAR deserialization via the ‘zbscrmcsvimpf’ parameter in the 'zeroBSCRM_CSVImporterLitehtml_app' function in versions up to, and including, 5.3.1. While the function performs a nonce check, steps 2 and 3 of the check do not take any action upon a failed check. Thes...

CVSS:
7.5
Affected:
up to 5.3.1
Fixed in:
5.4.0
Disclosed:
Apr 18, 2023

CVE-2022-3342 on NVD →

Jetpack CRM <= 5.4.4 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Jetpack CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 5.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator-level access, and above, to inject arbitrary web...

CVSS:
4.4
Affected:
up to 5.4.4
Fixed in:
5.5.0
Disclosed:
Mar 5, 2023

CVE-2023-27429 on NVD →

Jetpack CRM &#8211; Clients, Leads, Invoices, Billing, Email Marketing, &amp; Automation [zero-bs-crm] < 5.5

unknown

[en] The Jetpack CRM WordPress plugin before 5.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins

Affected:
up to 5.5
Fixed in:
5.5
Disclosed:
Jan 9, 2023

CVE-2022-4497 on NVD →

Jetpack CRM <= 5.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Jetpack CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and including, 5.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web sc...

CVSS:
6.4
Affected:
up to 5.4.4
Fixed in:
5.5
Disclosed:
Dec 19, 2022

CVE-2022-4497 on NVD →

Jetpack CRM &#8211; Clients, Leads, Invoices, Billing, Email Marketing, &amp; Automation [zero-bs-crm] < 5.4.3

unknown

[en] The Jetpack CRM WordPress plugin before 5.4.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Affected:
up to 5.4.3
Fixed in:
5.4.3
Disclosed:
Dec 12, 2022

CVE-2022-3919 on NVD →

Jetpack CRM <= 5.4.2 - Authenticated (Administrator+) Cross-Site Scripting

medium

The Jetpack CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings in versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arb...

CVSS:
5.5
Affected:
up to 5.4.2
Fixed in:
5.4.3
Disclosed:
Nov 21, 2022

CVE-2022-3919 on NVD →

Jetpack CRM &#8211; Clients, Leads, Invoices, Billing, Email Marketing, &amp; Automation [zero-bs-crm] < 5.5.1

unknown

The plugin does not sanitise and escape a client&#039;s phone number field, which could allow client users to perform Cross-Site Scripting attacks.

Affected:
up to 5.5.1
Fixed in:
5.5.1

Jetpack CRM &#8211; Clients, Leads, Invoices, Billing, Email Marketing, &amp; Automation [zero-bs-crm] < 5.5.1

unknown

The plugin does not sanitise and escape the tax rate field and custom field placeholders, which could allow CRM Admin users to perform Cross-Site Scripting attacks against site Admins.

Affected:
up to 5.5.1
Fixed in:
5.5.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database