CVE-2026-67398
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.
| CWE | CWE-862 |
| Vendor | webpros |
| Product | whmcs |
| Published | Sep 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for webpros whmcs
Be the first to know when new unknown vulnerabilities affecting webpros whmcs are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
WebPros / WHMCS
4.5.0 โค 8.12.2 8.13.0 < 8.13.8 9.0.0 < 9.0.8
References
Credits
"boomerang"