WHMCS customers had their usernames, passwords and credit card numbers made public early this week as a result of a breach. A malicious tool called WHMcs 0-Day started popping up on underground forums a couple of months ago where cyber-criminals buy and sell tools and technologies they use. The vulnerability is supposed to allow a full blind SQL injection using a technique discovered by the seller. For a $6k fee, the tool helps the buyer get administrator passwords while granting him full remote access to all compromised installations via a web browser.”]
Source: https://www.bitdefender.com/blog/hotforsecurity/o-day-exploit-may-cause-whmcs-more-security-trouble/