CVE-2026-67398

Published Sep 4, 2026

Last updated 19 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-67398 is identified as a missing authorization vulnerability within the 2Checkout payment gateway module of WebPros' WHMCS billing and automation platform. This flaw enables an unauthenticated attacker to obtain a customer's personally identifiable information (PII) by accessing the gateway's endpoint under specific circumstances. The vulnerability impacts WHMCS installations across several versions, specifically from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, and all end-of-life versions starting from 4.5.0.

Description
Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.
Source
support@hackerone.com
NVD status
Deferred

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.2
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

Weaknesses

support@hackerone.com
CWE-862

Social media

Hype score
Not currently trending