CVE-2026-29204: WebPros Whmcs

Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Insufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using another user’s `addonId` without any ownership validation leading to unauthorized access to the victim's account.

Affected products

  • WebPros Whmcs: from 7.4.0, up to and including 18.12.2; from 18.13.0, before 18.13.3 (fixed in 18.13.3); from 9.0.0, before 9.0.4 (fixed in 9.0.4)

Published 2026-05-12. Last modified 2026-06-17.