Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.
Metrics
Affected Vendors & Products
References
History
Sat, 05 Sep 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Sep 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webpros
Webpros whmcs |
|
| Vendors & Products |
Webpros
Webpros whmcs |
Fri, 04 Sep 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | WHMCS 2Checkout Payment Gateway Missing Authorization Exposes Customer Data |
Fri, 04 Sep 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions. | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: hackerone
Published: 2026-09-03T23:57:15.810Z
Updated: 2026-09-04T19:48:08.664Z
Reserved: 2026-07-29T15:00:02.294Z
Link: CVE-2026-67398
Updated: 2026-09-04T19:48:03.419Z
Status : Deferred
Published: 2026-09-04T00:17:13.563
Modified: 2026-09-09T15:41:24.427
Link: CVE-2026-67398
No data.