ZeroHour

CVE-2026-16037

niche

Timing side channel in PayTR Virtual POS iFrame API WHMCS module leaks secrets

CVSS 3.1
7.5 high
EPSS
<1%p23
Published
()
Modified
AI analysis

CVE-2026-16037 is an observable timing discrepancy (CWE-208) in the PayTR Virtual POS iFrame API v9x module for WHMCS, in which operations that should take constant time complete at measurably different speeds. A remote, unauthenticated attacker can send crafted requests and measure response-time differences to perform black-box reverse engineering of the module's secret verification logic. The scored impact is high confidentiality loss (CVSS C:H), potentially allowing reconstruction of the module's secret key material used to secure PayTR payment callbacks. It affects hosting businesses and resellers running WHMCS with the PayTR iFrame API module v9.0.0 through before v9.0.3 to accept PayTR payments. There is no public proof of concept, it is not listed in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days, so no exploitation is currently known.

What to do: Upgrade the PayTR Virtual POS iFrame API WHMCS module to v9.0.3 or later and verify the installed version in the WHMCS module settings. Sites that cannot update immediately should review payment callback logs for anomalies and consider restricting network access to the WHMCS endpoints. No workaround for the timing channel itself is known, so updating is the primary mitigation.

Affected
PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Modulefrom v9.0.0 before v9.0.3 (fixed in v9.0.3)
Estimated exposure
nichelow hundreds to low thousands of WHMCS deployments (estimate) — Only WHMCS hosting/reseller sites that integrate this Turkey-focused PayTR payment module are exposed, and no public active-install counts exist for the module, so the affected base is a small subset of the WHMCS install base.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Observable timing discrepancy vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Black Box Reverse Engineering. This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.

Weakness
CWE-208
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.