Description
Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.
Published: 2026-09-03
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Customer Data Exposure
Action: Apply Workaround
AI Analysis

Impact

The missing authorization flaw in WHMCS's 2Checkout payment gateway lets an unauthenticated user retrieve customer data via the gateway endpoint under specific conditions. It is present in WHMCS versions 8.13.0 through 8.13.6, 9.0.0 through 9.0.7, and all end‑of‑life releases starting at 4.5.0. without authentication.

Affected Systems

The issue affects WHMCS installations from version 8.13.0 up to, but not including, 8.13.7; from 9.0.0 up to, but not including, 9.0.8; and all end‑of‑life releases starting at 4.5.0. These versions use the 2Checkout gateway, so any WHMCS site running them is at risk until the gateway is disabled or the software is updated.

Risk and Exploitability

The vulnerability is rated high with a CVSS base score of 8.2, indicating significant impact if exploited. EPSS is less than 1%, and the flaw is not listed in the CISA KEV catalogue. The missing authorization flaw is exploitable by unauthenticated users accessing the 2Checkout gateway endpoint when certain conditions are met, allowing attackers to retrieve customer data from anywhere over the network and leaving the exploitation window large due to lack of authentication.

Generated by OpenCVE AI on September 21, 2026 at 05:51 UTC.

Remediation

Vendor Workaround

Deactivate 2Checkout payment gateway.


OpenCVE Recommended Actions

  • Disable or deactivate the 2Checkout payment gateway to block unauthenticated access.
  • Upgrade WHMCS to a fixed release (8.13.8 or later, 9.0.8 or later, or any supported non‑EOL version).
  • Verify that the 2Checkout endpoint is no longer reachable by attempting unauthenticated requests or using web vulnerability scanners.
  • Stay informed of WHMCS security advisories and apply any subsequent patches.

Generated by OpenCVE AI on September 21, 2026 at 05:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title WHMCS 2Checkout Payment Gateway Missing Authorization Exposes Customer Data

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions. Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.

Sat, 05 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Webpros
Webpros whmcs
Vendors & Products Webpros
Webpros whmcs

Fri, 04 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title WHMCS 2Checkout Payment Gateway Missing Authorization Exposes Customer Data

Fri, 04 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Description Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-09-14T20:53:05.678Z

Reserved: 2026-07-29T15:00:02.294Z

Link: CVE-2026-67398

cve-icon Vulnrichment

Updated: 2026-09-04T19:48:03.419Z

cve-icon NVD

Status : Deferred

Published: 2026-09-04T00:17:13.563

Modified: 2026-09-14T21:17:25.283

Link: CVE-2026-67398

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T06:00:09Z

Weaknesses