Input validation vulnerability in Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation 5.5.0

The Jetpack CRM plugin for WordPress is vulnerable to malicious code being stored in it. Versions up to and including 5.5.0, have an issue with the client phone number field not properly protecting the plugin from this malicious code. Attackers with the right access can inject code into a page which will then execute when the page is accessed. This can be used to do harm to the page and its users.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.