Impact
A missing authorization flaw in the 2Checkout payment gateway of WHMCS allows an unauthenticated user to retrieve customer data through a specific endpoint. This flaw can lead to the disclosure of sensitive client information and constitutes a serious confidentiality breach.
Affected Systems
The issue affects WHMCS installations from version 8.13.0 up to, but not including, 8.13.8; from 9.0.0 up to, but not including, 9.0.8; and all end‑of‑life releases starting at 4.5.0. These versions use the 2Checkout gateway, so any WHMCS site running them is at risk until the gateway is disabled or the software is updated.
Risk and Exploitability
The vulnerability is rated high with a CVSS base score of 8.2, indicating a significant impact if exploited. EPSS information is not available, but the security advisory notes the flaw is exploitable by unauthenticated users accessing the gateway endpoint; the flaw is not yet listed in CISA’s KEV catalogue. Attackers can leverage the exposed endpoint from anywhere over the network, and because no authentication is required, the window for exploitation is large.
OpenCVE Enrichment