ZeroHour

CVE-2026-16025

niche

Quantity Input Validation Flaw in PayTR Virtual Pos iFrame API WHMCS Module Enables DoS

CVSS 3.1
7.5 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-16025 is an improper validation of quantity input (CWE-1284) in the PayTR Virtual Pos iFrame API (v9x) payment module for WHMCS, which allows attackers to manipulate input data accepted by the module. An unauthenticated remote attacker can trigger the flaw by sending crafted quantity values through the module's network-facing payment interface, with no user interaction or credentials required. Per the published CVSS vector, the impact is confined to availability: manipulated input can disrupt or take down the affected payment/checkout service, with no confidentiality or integrity impact described. Anyone running WHMCS with the PayTR Virtual Pos iFrame API (v9x) module installed in versions 9.0.0 up to (but not including) 9.0.3 is affected, which mainly means hosting and reseller businesses using the Turkish PayTR payment gateway. No exploitation has been reported, no public proof-of-concept exists, EPSS is low (0.3%), and the issue is not in CISA's KEV catalog.

What to do: Upgrade the PayTR Virtual Pos iFrame API (v9x) WHMCS module to version 9.0.3 or later. Administrators who cannot patch immediately should check the installed module version in their WHMCS module management panel and monitor the WHMCS checkout/payment callback endpoints for availability problems or crash events, since the rated impact is a denial of service.

Affected
PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module>= 9.0.0, < 9.0.3
Estimated exposure
nichelikely only a few hundred to a few thousand WHMCS installations (estimated) — The vulnerable component is a single payment-gateway module for one Turkish payment provider within the WHMCS hosting-billing platform, so only the small subset of WHMCS deployments using PayTR checkout is exposed; no public active-install…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper validation of specified quantity in input vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Input Data Manipulation. This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.

Weakness
CWE-1284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.