---
id: CVE-2026-67398
title: >-
  Missing authorization vulnerability has been discovered in 2Checkout payment
  gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9.0.8, all other
  EOL versions from 4.5.0
summary: >-
  Missing authorization vulnerability has been discovered in 2Checkout payment
  gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9.0.8, all other
  EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to
  get …
severity: high
cvss: 8.2
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-862
vendor: WebPros
product: WHMCS
affected:
  - WHMCS >= 4.5.0 < 8.12.2
  - WHMCS >= 8.13.0 < 8.13.7
  - WHMCS >= 9.0.0 < 9.0.8
published: '2026-09-04'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T21:17:25.283'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-67398'
references:
  - url: >-
      https://help.whmcs.com/m/125386/l/2116695-cve-2026-67398-whmcs-security-update-2026-09-03
    label: support@hackerone.com
tags:
  - nvd
  - cve.org
epss: 0.00475
epssPercentile: 0.38401
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-04T19:47:54.274188Z'
cvssSource: cna
ingestedAt: '2026-09-09T16:14:05.518Z'
---

## Overview

Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
