CVE-2026-16025 PUBLISHED

Improper Payment Validation in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Module

Assigner: TR-CERT
Reserved: 17.07.2026 Published: 08.09.2026 Updated: 08.09.2026

Improper validation of specified quantity in input vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Input Data Manipulation.

This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 7.5

Product Status

Vendor PayTR Payment and Electronic Money Institution Inc.
Product PayTR Virtual Pos iFrame API (v9x) WHMCS Module
Versions Default: unaffected
  • affected from v9.0.0 to v9.0.3 (excl.)

Credits

  • Efe KIRBAŞ finder

References

Problem Types

  • CWE-1284 Improper validation of specified quantity in input CWE

Impacts

  • CAPEC-153 Input Data Manipulation