CVE-2026-22356 | Automattic Jetpack CRM Plugin up to 6.7.0 on WordPress filename control
A vulnerability, which was classified as critical, was found in Automattic Jetpack CRM Plugin up to 6.7.0 on WordPress. Impacted is an unknown function. Such manipulation leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is uniquely identified as CVE-2026-22356. The attack can be launched remotely. No exploit exists.