PLUGIN SECURITY

Is Zero Bs Crm safe?

The CRM for small businesses. Manage leads, invoicing, billing, email marketing, clients, contacts, quotes, automation. Works with WooCommerce too.

What this plugin does

  • Slug: zero-bs-crm
  • Author: Automattic
  • 30000+ active installs
  • 86/100 rating (152 reviews on wordpress.org)
  • 1969750 all-time downloads
  • On WordPress.org since 2016-07-04

client portalcrmlead generationmarketing automationWooCommerce CRM

Maintenance status

  • Latest known version: 6.8.2
  • Last updated: 2026-08-18 1:47pm GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): <8.0

Known vulnerabilities

5 known CVEs on file for Zero Bs Crm. Reported between 2022 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-22356 Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation [zero-bs-crm] < 6.7.1 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') High 7.5 < 6.7.1 6.7.1 2026-02-16 ✓ fixed in latest
Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation [zero-bs-crm] < 4.2.4 Unknown < 4.2.4 4.2.4 2024-10-28 ✓ fixed in latest
Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation [zero-bs-crm] < 5.5.1 Unknown < 5.5.1 5.5.1 2023-09-12 ✓ fixed in latest
Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation [zero-bs-crm] < 5.5.1 Unknown < 5.5.1 5.5.1 2023-09-12 ✓ fixed in latest
CVE-2022-3342 Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation [zero-bs-crm] < 5.4.0 Deserialization of Untrusted Data High 8.8 < 5.4.0 5.4.0 2023-04-18 ✓ fixed in latest
CVE-2023-27429 Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation [zero-bs-crm] < 5.5.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.9 < 5.5.0 5.5.0 2023-03-05 ✓ fixed in latest
CVE-2022-4497 Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation [zero-bs-crm] < 5.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.5 5.5 2022-12-19 ✓ fixed in latest
CVE-2022-3919 Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation [zero-bs-crm] < 5.4.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 5.4.3 5.4.3 2022-11-21 ✓ fixed in latest
+ 5 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation [zero-bs-crm] < 5.5.1 Unknown < 5.5.1 5.5.1 ✓ fixed in latest
Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation [zero-bs-crm] < 5.5.1 Unknown < 5.5.1 5.5.1 ✓ fixed in latest
Jetpack CRM < 5.5.1 - Client+ XSS Unknown < 5.5.1 5.5.1 ✓ fixed in latest
Jetpack CRM < 5.5.1 - CRM Admin+ XSS Unknown < 5.5.1 5.5.1 ✓ fixed in latest
Jetpack CRM WooCommerce Connect < 2.13 - Unauthorized Invoice Disclosure Unknown < 4.2.4 4.2.4 ✓ fixed in latest

How to fix it

Keep Zero Bs Crm updated — 6.8.2 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.