Executive brief
PayTR Virtual Pos is a payment processing module for WHMCS (a hosting and billing platform used by service providers). An improper validation flaw in the API allows attackers to manipulate input data, potentially enabling unauthorized transaction modifications or payment fraud without proper authorization checks.
Technical details
The vulnerability exists in PayTR Virtual Pos iFrame API (v9x) WHMCS Module versions prior to v9.0.3 and stems from improper validation of input quantity parameters. The flaw allows an attacker to manipulate input data by sending crafted requests with modified quantity values that bypass server-side validation checks. This is a network-accessible vulnerability that does not require authentication, allowing an unauthenticated attacker to modify transaction details. The attack could enable payment fraud, unauthorized price modifications, or other transaction tampering. A patch addressing this issue is available in version v9.0.3 and later.
Affected products
- PayTR Payment and Electronic Money Institution Inc. Virtual Pos iFrame API WHMCS Module v9.0.0 to before v9.0.3
Timeline
- 2026-09-08: disclosed