Security Advisory: WHMCS Admin Password Reset Weak Token
This is a security release for WHMCS. Update the product on every affected server to the patched release — there is no workaround, and unpatched servers remain exposed until updated.
Affected Versions
WHMCS 8.9.0 and earlier
Patched Version
WHMCS 8.10.1
Default Update CMD
yum update -y
Fix Commands
All Systems
Back up /var/www/html/whmcs
Download the patched release
Run the upgrade wizard at /install/upgrade
What this means under a SharedLicense license
Your SharedLicense license itself is not affected — this is a change in WHMCS software, not in licensing. Apply it on every affected server: update to the fixed release from the WHMCS Admin Area. Licenses keep working through updates; nothing needs re-issuing or re-activating.
References
Check your system for vulnerabilities
Select your product and operating system to see the exact fix commands that apply to you.
Check Your System