CVE-2026-16272
nicheUse of Less-Trusted Source in PayTR Virtual Pos iFrame API WHMCS Module (9.x)
CVE-2026-16272 is a 'use of less trusted source' flaw (CWE-348) in the PayTR Virtual Pos iFrame API (v9x) WHMCS Module, the payment-gateway integration that connects WHMCS billing installations to the Turkish payment provider PayTR. The module relies on data, including payment and order identifiers, obtained from a less-trusted source rather than strictly validating it against PayTR's trusted source, which allows exploitation of trusted identifiers. An unauthenticated remote attacker (per the CVSS vector: network vector, low complexity, no privileges, no user interaction) can send crafted values that the module accepts as legitimate, yielding high-impact confidentiality and integrity consequences — for example tampering with payment-related data processed through the integration — with no availability impact. Any WHMCS deployment running the affected module versions 9.0.0 through before 9.0.3 is affected. There are currently no known public proofs-of-concept, the flaw is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported.
What to do: Upgrade the PayTR Virtual Pos iFrame API (v9x) WHMCS Module to version 9.0.3 or later. Operators running 9.0.0–9.0.2 should review recent transaction and invoice records in WHMCS and reconcile them against the PayTR merchant panel for anomalies (unexpected payment confirmations or altered identifiers) until patched. Monitor the PayTR/USOM advisory for any follow-up guidance or PoC disclosure.
| PayTR Payment and Electronic Money Institution Inc. (PayTR) PayTR Virtual Pos iFrame API (v9x) WHMCS Module | from 9.0.0 before 9.0.3 (i.e., 9.0.0 through 9.0.2) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Exploitation of Trusted Identifiers. This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.
- Weakness
- CWE-348
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.