Multiple security vulnerabilities affecting WebPros WHMCS versions These WHMCS vulnerabilities impact all WHMCS 9 have been identified in WHMCS, allowing unauthenticated remote attackers to execute arbitrary code and harvest sensitive client details. The flaws impact all WHMCS 9.x installations prior to 9.0.8 and affect WHMCS 8.x releases prior to 8.13.7. Administrators should apply the released updates immediately to protect their web hosting operations.
CVE-2026-67399 (CVSS 9.3 — Critical): A security vulnerability involving the submission of forged payloads without adequate restrictions has been identified in WHMCS 8.0.x and later.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting WebPros WHMCS versions These WHMCS vulnerabilities impact all WHMCS 9 have been identified in WHMCS, allowing unauthenticated remote attackers to execute arbitrary code and harvest sensitive client details. The flaws impact all WHMCS 9.x installations prior to 9.0.8 and affect WHMCS 8.x releases prior to 8.13.7. Administrators should apply the released updates immediately to protect their web hosting operations.
CVE-2026-67399 (CVSS 9.3 — Critical): A security vulnerability involving the submission of forged payloads without adequate restrictions has been identified in WHMCS 8.0.x and later.[emaillocker id="1283"]
CVE-2026-67398: An unauthenticated user could retrieve personally identifiable information for a client, including name, address, city, state, postal code, country, email, and phone number, by querying the payment handler to access private customer directories.
These vulnerabilities collectively present a significant risk to web hosting providers using WHMCS.
We recommend you to update WHMCS to version 9.0.8.
The following reports contain further technical details:
[/emaillocker]