๐Ÿ” CVE Alert

CVE-2026-67398

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.

CWE CWE-862
Vendor webpros
Product whmcs
Published Sep 3, 2026
Stay Ahead of the Next One

Get instant alerts for webpros whmcs

Be the first to know when new unknown vulnerabilities affecting webpros whmcs are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

WebPros / WHMCS
4.5.0 โ‰ค 8.12.2 8.13.0 < 8.13.8 9.0.0 < 9.0.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
help.whmcs.com: https://help.whmcs.com/m/125386/l/2116695-cve-2026-67398-whmcs-security-update-2026-09-03

Credits

"boomerang"