CVE-2026-29204 PUBLISHED

Assigner: hackerone
Reserved: 04.03.2026 Published: 12.05.2026 Updated: 12.05.2026

Insufficient ownership check in clientarea.php allows an authenticated client area user to submit requests using another user’s addonId without any ownership validation leading to unauthorized access to the victim's account.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Score: 9.1

Product Status

Vendor WebPros
Product WHMCS
Versions Default: unaffected
  • affected from 7.4.0 to 18.12.2 (incl.)
  • affected from 18.13.0 to 18.13.3 (excl.)
  • affected from 9.0.0 to 9.0.4 (excl.)

References

Problem Types

  • CWE-639 Insecure Direct Object Reference (IDOR) CWE