Use of Less Trusted Source Vulnerability in PayTR Virtual Pos iFrame API
CVE-2026-16272
9.1CRITICAL
Key Information:
- Vendor
- CVE Published:
- 9 September 2026
What is CVE-2026-16272?
A security flaw in the PayTR Virtual Pos iFrame API (v9x) WHMCS Module permits exploitation due to reliance on less trusted sources. This vulnerability could allow attackers to manipulate trusted identifiers, potentially compromising payment security. It affects all versions from v9.0.0 to prior to v9.0.3, underlining the importance of immediate updates to secure systems against possible exploitation.
Affected Version(s)
PayTR Virtual Pos iFrame API (v9x) WHMCS Module v9.0.0
