Security · September 17, 2026

WebPros releases urgent patches for critical WHMCS flaws

macro shot of stainless steel padlock
Jose Fontano / Unsplash

WebPros International has issued security updates for its WHMCS billing management software to address two severe vulnerabilities. The company released the patches to protect hosting and cloud service providers from unauthorized access and data exposure. The fixes are available for immediate deployment to secure affected installations.

The security advisory was published on September 3, 2026, detailing the specific risks associated with the software. Both vulnerabilities were reported through the company's security program. The affected versions vary depending on the specific flaw, requiring administrators to verify their current software version against the provided guidance.

The first vulnerability, identified as CVE-2026-67399, stems from the deserialization of untrusted data. This flaw allows an attacker to execute arbitrary code on the server without requiring authentication under specific conditions. Such an exploit could compromise the entire installation environment and related data, leading to a significant breach of system integrity.

The second vulnerability, labeled CVE-2026-67398, affects the 2CheckOut payment gateway module. It results from a lack of proper authorization checks. This issue enables unauthorized users to access sensitive personal information, including customer names, addresses, email addresses, and phone numbers, without needing to log in or provide credentials.

HackerOne, the platform that assigned the Common Vulnerabilities and Exposures identifiers, evaluated the severity of these issues. The deserialization flaw received a base score of 9.3 under the CVSS version 4.0 standard, classifying it as critical. The authorization bypass in the payment module was rated with a base score of 8.2, placing it in the high severity category.

To mitigate these risks, WebPros released WHMCS version 9.0.8 and version 8.13.7, which contain the necessary fixes. The company strongly urges all users to update their systems to these versions as soon as possible. For the payment gateway issue, a temporary workaround is available by disabling the 2CheckOut module until the update can be applied.