Description
Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.
Published: 2026-09-03
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization flaw in the 2Checkout payment gateway of WHMCS allows an unauthenticated user to retrieve customer data through a specific endpoint. This flaw can lead to the disclosure of sensitive client information and constitutes a serious confidentiality breach.

Affected Systems

The issue affects WHMCS installations from version 8.13.0 up to, but not including, 8.13.8; from 9.0.0 up to, but not including, 9.0.8; and all end‑of‑life releases starting at 4.5.0. These versions use the 2Checkout gateway, so any WHMCS site running them is at risk until the gateway is disabled or the software is updated.

Risk and Exploitability

The vulnerability is rated high with a CVSS base score of 8.2, indicating a significant impact if exploited. EPSS information is not available, but the security advisory notes the flaw is exploitable by unauthenticated users accessing the gateway endpoint; the flaw is not yet listed in CISA’s KEV catalogue. Attackers can leverage the exposed endpoint from anywhere over the network, and because no authentication is required, the window for exploitation is large.

Generated by OpenCVE AI on September 4, 2026 at 01:22 UTC.

Remediation

Vendor Workaround

Deactivate 2Checkout payment gateway.


OpenCVE Recommended Actions

  • Disable or deactivate the 2Checkout payment gateway to block unauthenticated access.
  • Upgrade WHMCS to a fixed release (8.13.8 or later, 9.0.8 or later, or any supported non‑EOL version).
  • Verify that the 2Checkout endpoint is no longer reachable by attempting unauthenticated requests or using web vulnerability scanners.
  • Stay informed of WHMCS security advisories and apply any subsequent patches.

Generated by OpenCVE AI on September 4, 2026 at 01:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title WHMCS 2Checkout Payment Gateway Missing Authorization Exposes Customer Data

Fri, 04 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Description Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-09-03T23:57:15.810Z

Reserved: 2026-07-29T15:00:02.294Z

Link: CVE-2026-67398

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-04T00:17:13.563

Modified: 2026-09-04T00:17:13.563

Link: CVE-2026-67398

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T01:30:04Z

Weaknesses