Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all...
Description
Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.
AI Analyst Comment
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Description Summary:
A missing authorization vulnerability in the 2Checkout payment gateway for WHMCS allows unauthenticated attackers to retrieve sensitive customer data via a specific API endpoint.
Executive Summary:
A critical missing authorization flaw in the WHMCS 2Checkout payment gateway exposes sensitive customer information to unauthenticated remote attackers.
Vulnerability Details
CVE-ID: CVE-2026-67398
Affected Software: WebPros WHMCS
Affected Versions: 4.5.0 through 8.12.2, 8.13.0 up to 8.13.8, 9.0.0 up to 9.0.8
Vulnerability: The application fails to perform proper authorization checks within the 2Checkout payment gateway module. This allows an unauthenticated user to interact with a specific endpoint and exfiltrate customer data.
Business Impact
The vulnerability poses a severe risk to data privacy and regulatory compliance. Unauthorized access to customer records can lead to significant reputational damage, potential legal liabilities, and loss of client trust. With a CVSS score of 8.2, this high-severity flaw requires immediate attention to prevent the compromise of sensitive billing and personal information.
Remediation Plan
Immediate Action: Update the WHMCS installation to the latest patched version provided by WebPros as outlined in the vendor security advisory.
Proactive Monitoring: Review access logs for unusual requests directed toward the 2Checkout payment gateway endpoint and monitor for patterns of unauthorized data retrieval.
Compensating Controls: Implement Web Application Firewall (WAF) rules to restrict access to the vulnerable payment gateway endpoint, if an immediate update is not feasible.
Exploitation Status
Public Exploit Available: No — there is no confirmed public exploit in the available data.
Analyst Notes: As of September 4, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw's reliance on a missing authorization check makes it a straightforward target for automated scanning once the mechanism is understood.
Analyst Recommendation
Given the exposure of sensitive customer data, this vulnerability must be treated as a high-priority item. Organizations utilizing the 2Checkout gateway within WHMCS should verify their current version against the affected ranges and apply the vendor-supplied patches immediately to ensure the integrity and confidentiality of their customer database.