Impact
The missing authorization flaw in WHMCS's 2Checkout payment gateway lets an unauthenticated user retrieve customer data via the gateway endpoint under specific conditions. It is present in WHMCS versions 8.13.0 through 8.13.6, 9.0.0 through 9.0.7, and all end‑of‑life releases starting at 4.5.0. without authentication.
Affected Systems
The issue affects WHMCS installations from version 8.13.0 up to, but not including, 8.13.7; from 9.0.0 up to, but not including, 9.0.8; and all end‑of‑life releases starting at 4.5.0. These versions use the 2Checkout gateway, so any WHMCS site running them is at risk until the gateway is disabled or the software is updated.
Risk and Exploitability
The vulnerability is rated high with a CVSS base score of 8.2, indicating significant impact if exploited. EPSS is less than 1%, and the flaw is not listed in the CISA KEV catalogue. The missing authorization flaw is exploitable by unauthenticated users accessing the 2Checkout gateway endpoint when certain conditions are met, allowing attackers to retrieve customer data from anywhere over the network and leaving the exploitation window large due to lack of authentication.
OpenCVE Enrichment