CVE-2026-16037
nicheTiming side channel in PayTR Virtual POS iFrame API WHMCS module leaks secrets
CVE-2026-16037 is an observable timing discrepancy (CWE-208) in the PayTR Virtual POS iFrame API v9x module for WHMCS, in which operations that should take constant time complete at measurably different speeds. A remote, unauthenticated attacker can send crafted requests and measure response-time differences to perform black-box reverse engineering of the module's secret verification logic. The scored impact is high confidentiality loss (CVSS C:H), potentially allowing reconstruction of the module's secret key material used to secure PayTR payment callbacks. It affects hosting businesses and resellers running WHMCS with the PayTR iFrame API module v9.0.0 through before v9.0.3 to accept PayTR payments. There is no public proof of concept, it is not listed in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days, so no exploitation is currently known.
What to do: Upgrade the PayTR Virtual POS iFrame API WHMCS module to v9.0.3 or later and verify the installed version in the WHMCS module settings. Sites that cannot update immediately should review payment callback logs for anomalies and consider restricting network access to the WHMCS endpoints. No workaround for the timing channel itself is known, so updating is the primary mitigation.
| PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module | from v9.0.0 before v9.0.3 (fixed in v9.0.3) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Observable timing discrepancy vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Black Box Reverse Engineering. This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.
- Weakness
- CWE-208
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.