ZeroHour

CVE-2026-67398

moderate

Missing Authorization in WHMCS 2Checkout Payment Gateway Exposes Customer Data

CVSS 4.0
8.2 high
EPSS
<1%p20
Published
()
Modified
AI analysis

CVE-2026-67398 is a missing authorization flaw (CWE-862) in the 2Checkout payment gateway module of WHMCS, the web-hosting billing and automation platform. An unauthenticated remote attacker can send requests to the 2Checkout gateway's endpoint and, under specific conditions (not detailed in the available disclosure), retrieve WHMCS customer data. The impact is confidentiality-only — the CVSS 4.0 vector shows high confidential-data disclosure with no integrity or availability impact, no privileges or user interaction required. Affected deployments are WHMCS 8.13.0 through 8.13.7, 9.0.0 through 9.0.7, and all other end-of-life versions from 4.5.0 onward; installations that do not have the 2Checkout gateway module active are not exposed. There is currently no public proof-of-concept, the issue is not in CISA KEV, and EPSS puts near-term exploitation probability at 0.3% (20th percentile), so no confirmed exploitation is known.

What to do: Upgrade to WHMCS 8.13.8, 9.0.8, or a later supported release; sites running EOL versions from 4.5.0 must move to a supported fixed release. Deployments that do not use the 2Checkout gateway are unaffected, but as an interim measure disable the 2Checkout gateway module and review web logs for unauthenticated requests to its endpoint, then assess any accessed customer data for breach-notification obligations.

Affected
WHMCS (2Checkout payment gateway module)8.13.0 before 8.13.8 (fixed in 8.13.8)
WHMCS (2Checkout payment gateway module)9.0.0 before 9.0.8 (fixed in 9.0.8)
WHMCS (2Checkout payment gateway module)all other end-of-life versions from 4.5.0 onward (no in-line fix; remediate by upgrading to a supported fixed release)
Estimated exposure
moderate≈1,000–10,000 sites (subset of WHMCS installs with the 2Checkout gateway enabled) — WHMCS is deployed by tens of thousands of hosting and digital-services businesses, but 2Checkout is one of many optional gateway modules far less common than PayPal/Stripe, so only a minority of installations — plausibly in the low…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.

Weakness
CWE-862
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.