WHMCS released a vital security update on 3rd June 2025, impacting all currently supported versions of their systems: v8.13, v8.12, and v8.11. These updates help resolve several security vulnerabilities that have been identified as affecting all currently supported WHMCS versions.
This update resolves multiple security vulnerabilities, including cross-site scripting (XSS) and cross-site request forgery (CSRF), that were identified through a combination of internal security audits and responsible disclosures via WHMCS security Bounty Porgram.
Why this Matters to WHMCS Global Services Client Theme Users?
As the vulnerabilities were not directly within the WHMCS Global services themes or order forms, our products are developed using WHMCS core templates like “Twenty-One” and “Standard_Cart” which were impacted by the security patch.
Therefore, to ensure our client areas remain stable, secure, and fully compatible with WHMCS 8.11.x to 8.13.x, we have updated all affected components in our themes. Applying the updated patch or full version is vital to maintain seamless functionality and compliance with WHMCS’s latest security standards.
What Has Been Updated?
Our WHMCS themes ClientX, CloudX, HostX, TwentyX, and the One Step Order Form—leverage core JavaScript and CSS resources from WHMCS’s default “Twenty-One” theme and” Standard_Cart” order form template.
When you upgrade to the latest version of WHMCS or apply a security patch, these core files are automatically refreshed with the latest security enhancements.
At this time, a specific update is available only for our HostX WHMCS Web Hosting Template, compatible with WHMCS version 8.13.1. We’ve proactively updated the necessary files in the HostX theme to maintain full compatibility and enhanced security.
How to Download the Updated Files?
There is only an update available for our HostX WHMCS Web Hosting Template for WHMCS 8.13.1.
We have updated the relevant file in our HostX theme to ensure continued security and complete compatibility.
We recommend downloading the latest patch or updated package from your client’s area.
For Users on Older WHMCS Versions
WHMCS has not released security patches for versions below 8.11.x. No official fixes are available if you’re still using WHMCS 8.10 or earlier. To stay protected:
We strongly recommend upgrading to WHMCS 8.11 or higher as soon as possible.
Then, apply the matching updated theme or order form from your WHMCS Global Services client area.
Need Help?
If you need assistance applying the patch, upgrading your WHMCS version, or downloading the correct files, our support team is here to help. Contact our support team.