Junglewise Threat Intelligence

CVE-2026-16272: PayTR Virtual Pos iFrame API WHMCS Module trusted identifier exploitation

CVE-2026-16272 · Severity: critical · CVSS 9.1 · Published 2026-09-09

Executive brief

PayTR Virtual Pos is an e-commerce payment processing module for WHMCS hosting management systems. A vulnerability in versions 9.0.0 through 9.0.2 allows attackers to exploit trusted identifiers, potentially leading to unauthorized payment processing, customer data theft, or fraudulent transactions on affected hosting control panels.

Technical details

The PayTR Virtual Pos iFrame API WHMCS Module contains a use-of-less-trusted-source vulnerability that enables exploitation of trusted identifiers. The vulnerability resides in the iFrame API integration layer (v9x series) and allows attackers to leverage trusted identifier mechanisms to bypass authentication or authorization controls. Affected versions range from v9.0.0 to v9.0.2; version 9.0.3 or later addresses this issue. Attack vectors are network-based with no user interaction required. An attacker can exploit this to gain unauthorized access to payment processing functions, manipulate transactions, or access sensitive payment and customer data.

Affected products

  • PayTR Payment and Electronic Money Institution Inc. Virtual Pos iFrame API (v9x) WHMCS Module v9.0.0 to v9.0.2

Timeline

  • 2026-09-09: disclosed
  • 2026-09-09: patched: Fixed in version 9.0.3 or later

References