Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
Deactivate 2Checkout payment gateway.
References
History
Fri, 04 Sep 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions. | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-09-03T23:57:15.810Z
Reserved: 2026-07-29T15:00:02.294Z
Link: CVE-2026-67398
No data.
Status : Received
Published: 2026-09-04T00:17:13.563
Modified: 2026-09-04T00:17:13.563
Link: CVE-2026-67398
No data.
OpenCVE Enrichment
No data.
Weaknesses