A critical (CVSS 9.1) vulnerability in the PayTR Virtual Pos iFrame API (v9x) WHMCS Module lets unauthenticated remote attackers abuse trusted identifiers to compromise confidentiality and integrity in affected billing deployments.
What Is It
CVE-2026-16272 is a "use of less trusted source" weakness (CWE-348) in the PayTR Virtual Pos iFrame API (v9x) WHMCS Module, published by PayTR Payment and Electronic Money Institution Inc. USOM classifies the attack pattern as Exploitation of Trusted Identifiers.
Neither USOM nor the vendor has published a technical breakdown of the flaw, so the concrete mechanism is not established. The CWE-348 mapping, combined with the CVSS vector, is consistent with a module that reads the identifiers tying a payment to an order from the client-controlled side of the iFrame flow and treats them as authoritative rather than validating them against PayTR's own server-side response; which would let an unauthenticated attacker who can reach the module's callback endpoint choose those identifiers and have the module act on whatever it is handed. That reading is an inference from the classification, not a confirmed description of the code path, and the record is still awaiting NVD enrichment that could revise it.
The CVE was assigned and scored by USOM (Turkey's national CERT, [email protected]) and published on 2026-09-09.
Why It Matters
The CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, yielding a base score of 9.1 (CRITICAL) with a maximum exploitability sub-score of 3.9. In practical terms: the vulnerability is reachable over the network, requires low attack complexity, needs no privileges, and needs no user interaction. Impact is HIGH to both confidentiality and integrity; availability is unaffected.
That combination, trivially reachable, fully unauthenticated, and integrity-impacting in a payment module, is the worst-case profile for a component that sits in a billing and transaction path.
CVE-2026-16272 is not listed in the CISA Known Exploited Vulnerabilities catalog as of 2026-09-09. There is no confirmation of active exploitation, and no KEV-mandated remediation deadline or required action associated with it.
What's Vulnerable
- Vendor: PayTR Payment and Electronic Money Institution Inc.
- Product: PayTR Virtual Pos iFrame API (v9x) WHMCS Module
- Affected versions: v9.0.0 up to (but not including) v9.0.3
- Default status: unaffected; only the range above is flagged
No CPE entries were published with the record, so automated inventory matching will not catch this. Identify exposure by checking the module version directly in WHMCS installations.
Patch Status
The version data indicates the issue is resolved in v9.0.3. Operators running v9.0.0 through v9.0.2 should upgrade to v9.0.3 or later. The NVD record is still in Received status as of 2026-09-09, so enrichment and additional vendor detail may follow.
Sources
- NVD, CVE-2026-16272: https://nvd.nist.gov/vuln/detail/CVE-2026-16272
- USOM (TR-CERT) Security Advisory TR-26-1034: https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1034
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog