CVE-2026-16272
A critical flaw in PayTR's WHMCS module lets attackers use untrusted sources to trick the system into trusting them. The bug is present in versions 9.0.0 through 9.0.2 and can be fixed by updating the module.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
PayTR Virtual Pos iFrame API WHMCS Module, versions 9.0.0 to 9.0.2. Users running these versions on their WHMCS sites are at risk.
Real-world impact
An attacker could trick the payment system into accepting fraudulent transactions or manipulating payment data, potentially leading to financial loss.
Why this severity
The CVSS score of 9.1 reflects that the vulnerability can be exploited remotely with no authentication or user interaction, and it can compromise the confidentiality and integrity of payment information.
What to do about it
- 01Upgrade the PayTR Virtual Pos iFrame API WHMCS Module to version 9.0.3 or later.
NVD-referenced vendor advisory
Timeline
- Sep 9, 2026 · 5d agoPublishedDisclosed and added to the National Vulnerability Database.
- Sep 9, 2026 · 5d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.