The CRM's IMAP connector saved mail attachments without checking the extension or normalising the path, so a crafted email could drop a PHP file into wp-content/uploads. CVE-2026-18080, CVSS 9.8, fixed in 1.17.8.
Segurium Research writes these up from public source after the fix has
shipped. We do not scan or probe third-party sites, and no teardown
here carries a working exploit. Segurium itself is a WordPress malware
scanner on the official directory at
wordpress.org/plugins/segurium/.