VYPR
Unrated severityNVD Advisory· Published Sep 3, 2026

CVE-2026-67398

CVE-2026-67398

Description

Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1
  • Whmcs/Whmcsllm-fuzzy
    Range: 8.13.0 - 8.13.7, 9.0.0 - 9.0.7, 4.5.0 - EOL

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.