CVE-2026-16272 PUBLISHED

Client IP Spoofing via Untrusted HTTP Headers in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Module

Assigner: TR-CERT
Reserved: 20.07.2026 Published: 09.09.2026 Updated: 09.09.2026

Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Exploitation of Trusted Identifiers.

This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Score: 9.1

Product Status

Vendor PayTR Payment and Electronic Money Institution Inc.
Product PayTR Virtual Pos iFrame API (v9x) WHMCS Module
Versions Default: unaffected
  • affected from v9.0.0 to v9.0.3 (excl.)

Credits

  • Efe KIRBAŞ finder

References

Problem Types

  • CWE-348 Use of less trusted source CWE

Impacts

  • CAPEC-21 Exploitation of Trusted Identifiers