Back to Security Advisories

WHMCS 8.13.5 Security Update

Undisclosed Security Fix

High
WHMCS

Default Update CMD

Update WHMCS to the latest version via the Admin Area (Utilities > Update WHMCS).

8.13.5 (Maintenance Release) Security Fixes

WHMCS 8.13.5 is a security maintenance release. It bundles a number of security hardening changes. Below is an explanation of what each fix addresses, along with the affected versions and the update path.

Undisclosed Security Fix

WHMCS ships several security fixes each release without publishing technical detail. These are applied as hardening of the platform and are not accompanied by a public CVE, so the specific mechanism is withheld to protect installations that have not yet updated. Upgrading is the recommended course of action.

Improved security around Admin password resets.

Admin password reset requests now require stronger validation and confirmation, reducing the risk of account takeover via the reset flow.

Improved security around User password resets.

Client-area password resets received the same hardening, closing a path that could be abused to reset another user’s password.

Improved security around Invoice processing Hook Points

Invoice-related hook points now re-verify authorization before executing, stopping a crafted request from triggering actions the caller is not entitled to.

Improved security around User logouts.

Logout handling now properly invalidates the session, preventing a stale session from being reused after logout.

Undisclosed Security Fix

WHMCS ships several security fixes each release without publishing technical detail. These are applied as hardening of the platform and are not accompanied by a public CVE, so the specific mechanism is withheld to protect installations that have not yet updated. Upgrading is the recommended course of action.

Undisclosed Security Fix

WHMCS ships several security fixes each release without publishing technical detail. These are applied as hardening of the platform and are not accompanied by a public CVE, so the specific mechanism is withheld to protect installations that have not yet updated. Upgrading is the recommended course of action.

Improved security for paying invoices with Stripe

Stripe payment callbacks are validated more strictly against forged or replayed webhook payloads.

Improved security for paying invoices with PayPal Basic

The PayPal Basic gateway now verifies the authenticity of payment callbacks before marking an invoice as paid.

Improved security for paying invoices with PayPal Payments

The PayPal Payments gateway callback now validates the source and payload more strictly, preventing forged or replayed payment notifications.

Improved security of logging in WorldPay FuturePay

WorldPay FuturePay login and callback handling now validate the response more thoroughly, preventing authentication bypass.

Affected Versions and Remediation

Apply the update to the latest patch release of your WHMCS branch. WHMCS supports updating in place through the Admin Area (Utilities > Update WHMCS) or by uploading the release package. Back up both your WHMCS files and database before updating.

How to Apply the Fix

Update WHMCS to the latest patch release of your branch, then confirm the version in Help > About WHMCS.

Utilities → Update WHMCS (in the Admin Area)

Check your system for vulnerabilities

Selecciona tu producto y sistema operativo para ver los comandos de corrección exactos que se aplican a ti.

Check Your System