Junglewise Threat Intelligence

CVE-2026-16037: PayTR Virtual Pos iFrame API timing attack in WHMCS module

CVE-2026-16037 · Severity: high · CVSS 7.5 · Published 2026-09-08

Executive brief

PayTR Virtual Pos is a payment processing component integrated into WHMCS (a popular web hosting billing platform) via an iFrame API module. A timing-based vulnerability allows attackers to reverse-engineer security tokens or credentials through observable delays in API responses, potentially compromising payment transaction integrity and customer financial data.

Technical details

This vulnerability is an observable timing discrepancy (a side-channel attack vector) in the PayTR Virtual Pos iFrame API v9x WHMCS module, affecting versions 9.0.0 through 9.0.2. The flaw enables black-box reverse engineering by analyzing response time variations, which can leak information about internal validation logic or cryptographic keys. The attack is network-based and requires no authentication. Exploitation allows an attacker to recover sensitive authentication or transaction data. A patch is available in version 9.0.3 or later.

Affected products

  • PayTR Payment and Electronic Money Institution Inc. Virtual Pos iFrame API WHMCS Module 9.0.0 to 9.0.2

Timeline

  • 2026-09-08: disclosed: Published on NVD and Turkish National Cybersecurity Authority
  • 2026-09-08: patched: Fix available in version 9.0.3 or later

References

Related threats