Skip to content

Menu
  • Home
Menu

CVE-2026-67398 – WHMCS 2Checkout Payment Gateway Missing Authorization Vulnerability

Posted on September 4, 2026
CVE ID :CVE-2026-67398

Published : Sept. 4, 2026, 12:17 a.m. | 20 minutes ago

Description :Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer’s data via 2Checkout payment gateway’s endpoint under specific conditions.

Severity: 8.2 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Post Views: 1

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme