ZeroHour

CVE-2026-16272

niche

Use of Less-Trusted Source in PayTR Virtual Pos iFrame API WHMCS Module (9.x)

CVSS 3.1
9.1 critical
EPSS
<1%p4
Published
()
Modified
AI analysis

CVE-2026-16272 is a 'use of less trusted source' flaw (CWE-348) in the PayTR Virtual Pos iFrame API (v9x) WHMCS Module, the payment-gateway integration that connects WHMCS billing installations to the Turkish payment provider PayTR. The module relies on data, including payment and order identifiers, obtained from a less-trusted source rather than strictly validating it against PayTR's trusted source, which allows exploitation of trusted identifiers. An unauthenticated remote attacker (per the CVSS vector: network vector, low complexity, no privileges, no user interaction) can send crafted values that the module accepts as legitimate, yielding high-impact confidentiality and integrity consequences — for example tampering with payment-related data processed through the integration — with no availability impact. Any WHMCS deployment running the affected module versions 9.0.0 through before 9.0.3 is affected. There are currently no known public proofs-of-concept, the flaw is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported.

What to do: Upgrade the PayTR Virtual Pos iFrame API (v9x) WHMCS Module to version 9.0.3 or later. Operators running 9.0.0–9.0.2 should review recent transaction and invoice records in WHMCS and reconcile them against the PayTR merchant panel for anomalies (unexpected payment confirmations or altered identifiers) until patched. Monitor the PayTR/USOM advisory for any follow-up guidance or PoC disclosure.

Affected
PayTR Payment and Electronic Money Institution Inc. (PayTR) PayTR Virtual Pos iFrame API (v9x) WHMCS Modulefrom 9.0.0 before 9.0.3 (i.e., 9.0.0 through 9.0.2)
Estimated exposure
nichelikely hundreds to a few thousand WHMCS installations (Turkish merchants/resellers using the PayTR iFrame gateway) — WHMCS is deployed by tens of thousands of hosting and online-billing businesses, but this exposure is limited to the subset running this specific PayTR gateway module, which serves primarily the Turkish merchant market, implying an order…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Exploitation of Trusted Identifiers. This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.

Weakness
CWE-348
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.