Executive brief
WHMCS is a client management system widely used for billing, support ticketing, and service provisioning. The 2Checkout payment gateway integration in WHMCS contains an authorization flaw that allows unauthenticated attackers to retrieve sensitive customer information including names, addresses, email addresses, and phone numbers. This exposes personally identifiable information (PII) for any customer who has used the 2Checkout payment method.
Technical details
A missing authorization vulnerability exists in the 2Checkout payment gateway module of WHMCS, where specific endpoints fail to properly authenticate requests before returning customer data. The vulnerability is accessible to unauthenticated users under certain conditions and allows retrieval of personally identifiable information (PII) such as client names, addresses, email, and phone numbers. The flaw affects WHMCS versions 4.5.0 through 8.13.6 and 9.0.0 through 9.0.7. Patches are available in WHMCS 8.13.7 and 9.0.8; as a temporary workaround, the 2Checkout payment gateway module can be deactivated in system settings.
Affected products
- WHMCS WHMCS 4.5.0 through 8.13.6, 9.0.0 through 9.0.7
Timeline
- 2026-09-03: disclosed
- 2026-09-03: patched: WHMCS 8.13.7 and 9.0.8 released with fixes