PHP Remote File Inclusion Vulnerability in Automattic Jetpack CRM
CVE-2026-22356
7.5HIGH
What is CVE-2026-22356?
A vulnerability exists in Automattic Jetpack CRM that allows for PHP Local File Inclusion due to improper handling of filenames in include or require statements. An attacker could exploit this vulnerability to gain unauthorized access to sensitive files on the server, potentially leading to more severe attacks. This affects versions of Jetpack CRM up to 6.7.0.
Affected Version(s)
Jetpack CRM 0 <= 6.7.0