Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2026-29204-whmcs-clientarea-addonid — Provides community notes and an optional temporary hook to guard against CVE-2026-29204, a WHMCS client area addonId ownership vulnerability, with upgrade guidance. | Kitploit
Tools/GitHubGitHub/bogdanrotariu/cve-2026-29204-whmcs-clientarea-addonid
Authentication & AuthorizationVulnerability AnalysisWeb SecurityMisconfigurationLearning & EducationCurated Resources
GitHubbogdanrotariu/cve-2026-29204-whmcs-clientarea-addonid

cve-2026-29204-whmcs-clientarea-addonid

Provides community notes and an optional temporary hook to guard against CVE-2026-29204, a WHMCS client area addonId ownership vulnerability, with upgrade guidance.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
134 months agoNot yet reviewed

CVE-2026-29204 — WHMCS client area addon guard

Unofficial community notes for CVE-2026-29204: on clientarea.php?action=productdetails, a logged-in client can supply a foreign addonId with modop=custom and reach module context that does not belong to the session.

Upgrade first. Apply a vendor-patched WHMCS build (8.13.3 or 9.0.4 on supported branches). See the 8.13 and 9.0 change logs.

The hook in mitigation/ is a temporary, optional client-area guard. It is not a vendor patch and not a substitute for upgrading. Remove it after patching unless you keep a separate, documented policy.

Install (optional bridge)

cp mitigation/includes/hooks/cve_addonid_clientarea_guard.php /path/to/whmcs/includes/hooks/

The hook checks addonId ownership against the session client and the service id on productdetails with modop=custom, then redirects foreign requests. It does not depend on client-area language strings. Blocked attempts are recorded in Utilities → Logs → Activity Log.

Disclaimer

Provided as is, without warranty. Not affiliated with WHMCS. Use only on systems you own or are authorized to change. You are responsible for backups, testing, and compliance. The authors do not guarantee that this hook prevents abuse or replaces a vendor security update.

Download Tool