CVE-2026-67398: High severity WHMCS WHMCS vulnerability
Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WHMCSto a version that resolves this vulnerability.Fixed in 8.13.8 - Upgrade
Upgrade
WHMCSto a version that resolves this vulnerability.Fixed in 9.0.8
Event History
Frequently Asked Questions
Which releases should be updated?
Update WHMCS 8.13 installations to 8.13.8 or later and 9.0 installations to 9.0.8 or later. The issue affects versions before those releases.
Does exploitation require an authenticated WHMCS account?
No. The vulnerability can allow an unauthenticated user to obtain WHMCS customer data through the 2Checkout payment gateway endpoint when specific conditions are met.
Are end-of-life WHMCS versions affected?
Yes. All other end-of-life versions beginning with 4.5.0 are identified as affected. The provided information does not list a fixed release for those versions.