CVE-2026-16037 PUBLISHED

Callback Authentication Bypass via Timing Attack in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Module

Assigner: TR-CERT
Reserved: 17.07.2026 Published: 08.09.2026 Updated: 08.09.2026

Observable timing discrepancy vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Black Box Reverse Engineering.

This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 7.5

Product Status

Vendor PayTR Payment and Electronic Money Institution Inc.
Product PayTR Virtual Pos iFrame API (v9x) WHMCS Module
Versions Default: unaffected
  • affected from v9.0.0 to v9.0.3 (excl.)

Credits

  • Efe KIRBAŞ finder

References

Problem Types

  • CWE-208 Observable timing discrepancy CWE

Impacts

  • CAPEC-189 Black Box Reverse Engineering