Use of Less Trusted Source Vulnerability in PayTR Virtual Pos iFrame API
CVE-2026-16272

9.1CRITICAL

What is CVE-2026-16272?

A security flaw in the PayTR Virtual Pos iFrame API (v9x) WHMCS Module permits exploitation due to reliance on less trusted sources. This vulnerability could allow attackers to manipulate trusted identifiers, potentially compromising payment security. It affects all versions from v9.0.0 to prior to v9.0.3, underlining the importance of immediate updates to secure systems against possible exploitation.

Affected Version(s)

PayTR Virtual Pos iFrame API (v9x) WHMCS Module v9.0.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Efe KIRBAĹž
.