Whmcs · Whmcs · CVE-2026-67398
**Name of the Vulnerable Software and Affected Versions**
WHMCS versions 4.5.0 through 8.13.7
WHMCS versions 8.13.0 through 8.13.7
WHMCS versions 9.0.0 through 9.0.7
**Description**
A missing authorization issue exists in the 2Checkout payment gateway. This flaw allows an unauthenticated user to retrieve customer data through the 2Checkout payment gateway endpoint under specific conditions.
**Recommendations**
Update to version 8.13.8 or later.
Update to version 9.0.8 or later.
Update to a supported version beyond the EOL 4.5.0 range.