CVE-2026-67398
8.2WebPros · WHMCS
A missing authorization vulnerability in the 2Checkout payment gateway for WHMCS allows unauthenticated attackers to retrieve sensitive customer data via a specific API endpoint.
Executive summary
A critical missing authorization flaw in the WHMCS 2Checkout payment gateway exposes sensitive customer information to unauthenticated remote attackers.
Vulnerability
The application fails to perform proper authorization checks within the 2Checkout payment gateway module. This allows an unauthenticated user to interact with a specific endpoint and exfiltrate customer data.
Business impact
The vulnerability poses a severe risk to data privacy and regulatory compliance. Unauthorized access to customer records can lead to significant reputational damage, potential legal liabilities, and loss of client trust. With a CVSS score of 8.2, this high-severity flaw requires immediate attention to prevent the compromise of sensitive billing and personal information.
Remediation
Immediate Action: Update the WHMCS installation to the latest patched version provided by WebPros as outlined in the vendor security advisory.
Proactive Monitoring: Review access logs for unusual requests directed toward the 2Checkout payment gateway endpoint and monitor for patterns of unauthorized data retrieval.
Compensating Controls: Implement Web Application Firewall (WAF) rules to restrict access to the vulnerable payment gateway endpoint, if an immediate update is not feasible.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit in the available data.
Analyst recommendation
Given the exposure of sensitive customer data, this vulnerability must be treated as a high-priority item. Organizations utilizing the 2Checkout gateway within WHMCS should verify their current version against the affected ranges and apply the vendor-supplied patches immediately to ensure the integrity and confidentiality of their customer database.
More WebPros CVEs
Sources
Originally found and disclosed by "boomerang", per the CVE Program record.