Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
Deactivate 2Checkout payment gateway.
References
History
Fri, 04 Sep 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webpros
Webpros whmcs |
|
| Vendors & Products |
Webpros
Webpros whmcs |
Fri, 04 Sep 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | WHMCS 2Checkout Payment Gateway Missing Authorization Exposes Customer Data |
Fri, 04 Sep 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions. | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-09-03T23:57:15.810Z
Reserved: 2026-07-29T15:00:02.294Z
Link: CVE-2026-67398
No data.
Status : Received
Published: 2026-09-04T00:17:13.563
Modified: 2026-09-04T00:17:13.563
Link: CVE-2026-67398
No data.
OpenCVE Enrichment
Updated: 2026-09-04T02:00:05Z
Weaknesses