CVE-2026-16025
nicheQuantity Input Validation Flaw in PayTR Virtual Pos iFrame API WHMCS Module Enables DoS
CVE-2026-16025 is an improper validation of quantity input (CWE-1284) in the PayTR Virtual Pos iFrame API (v9x) payment module for WHMCS, which allows attackers to manipulate input data accepted by the module. An unauthenticated remote attacker can trigger the flaw by sending crafted quantity values through the module's network-facing payment interface, with no user interaction or credentials required. Per the published CVSS vector, the impact is confined to availability: manipulated input can disrupt or take down the affected payment/checkout service, with no confidentiality or integrity impact described. Anyone running WHMCS with the PayTR Virtual Pos iFrame API (v9x) module installed in versions 9.0.0 up to (but not including) 9.0.3 is affected, which mainly means hosting and reseller businesses using the Turkish PayTR payment gateway. No exploitation has been reported, no public proof-of-concept exists, EPSS is low (0.3%), and the issue is not in CISA's KEV catalog.
What to do: Upgrade the PayTR Virtual Pos iFrame API (v9x) WHMCS module to version 9.0.3 or later. Administrators who cannot patch immediately should check the installed module version in their WHMCS module management panel and monitor the WHMCS checkout/payment callback endpoints for availability problems or crash events, since the rated impact is a denial of service.
| PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module | >= 9.0.0, < 9.0.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper validation of specified quantity in input vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Input Data Manipulation. This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.
- Weakness
- CWE-1284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.