CVE-2026-67398
moderateMissing Authorization in WHMCS 2Checkout Payment Gateway Exposes Customer Data
CVE-2026-67398 is a missing authorization flaw (CWE-862) in the 2Checkout payment gateway module of WHMCS, the web-hosting billing and automation platform. An unauthenticated remote attacker can send requests to the 2Checkout gateway's endpoint and, under specific conditions (not detailed in the available disclosure), retrieve WHMCS customer data. The impact is confidentiality-only — the CVSS 4.0 vector shows high confidential-data disclosure with no integrity or availability impact, no privileges or user interaction required. Affected deployments are WHMCS 8.13.0 through 8.13.7, 9.0.0 through 9.0.7, and all other end-of-life versions from 4.5.0 onward; installations that do not have the 2Checkout gateway module active are not exposed. There is currently no public proof-of-concept, the issue is not in CISA KEV, and EPSS puts near-term exploitation probability at 0.3% (20th percentile), so no confirmed exploitation is known.
What to do: Upgrade to WHMCS 8.13.8, 9.0.8, or a later supported release; sites running EOL versions from 4.5.0 must move to a supported fixed release. Deployments that do not use the 2Checkout gateway are unaffected, but as an interim measure disable the 2Checkout gateway module and review web logs for unauthenticated requests to its endpoint, then assess any accessed customer data for breach-notification obligations.
| WHMCS (2Checkout payment gateway module) | 8.13.0 before 8.13.8 (fixed in 8.13.8) |
| WHMCS (2Checkout payment gateway module) | 9.0.0 before 9.0.8 (fixed in 9.0.8) |
| WHMCS (2Checkout payment gateway module) | all other end-of-life versions from 4.5.0 onward (no in-line fix; remediate by upgrading to a supported fixed release) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.
- Weakness
- CWE-862
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.