Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Deactivate 2Checkout payment gateway.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 04 Sep 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | WHMCS 2Checkout Payment Gateway Missing Authorization Exposes Customer Data |
Fri, 04 Sep 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions. | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-09-03T23:57:15.810Z
Reserved: 2026-07-29T15:00:02.294Z
Link: CVE-2026-67398
No data.
Status : Received
Published: 2026-09-04T00:17:13.563
Modified: 2026-09-04T00:17:13.563
Link: CVE-2026-67398
No data.
OpenCVE Enrichment
Updated: 2026-09-04T01:30:04Z