Back to Security Advisories

Security Advisory: WHMCS Admin Password Reset Weak Token

This is a security release for WHMCS. Update the product on every affected server to the patched release — there is no workaround, and unpatched servers remain exposed until updated.

High
WHMCS

Affected Versions

WHMCS 8.9.0 and earlier

Patched Version

WHMCS 8.10.1

Default Update CMD

yum update -y

Fix Commands

All Systems

Back up /var/www/html/whmcs
Download the patched release
Run the upgrade wizard at /install/upgrade

What this means under a SharedLicense license

Your SharedLicense license itself is not affected — this is a change in WHMCS software, not in licensing. Apply it on every affected server: update to the fixed release from the WHMCS Admin Area. Licenses keep working through updates; nothing needs re-issuing or re-activating.

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System