Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Exploitation of Trusted Identifiers. This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.
History

Thu, 10 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Paytr
Paytr paytr Virtual Pos Iframe Api (v9x) Whmcs Module
Vendors & Products Paytr
Paytr paytr Virtual Pos Iframe Api (v9x) Whmcs Module

Thu, 10 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Exploitation of Trusted Identifiers. This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.
Title Client IP Spoofing via Untrusted HTTP Headers in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Module
Weaknesses CWE-348
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published: 2026-09-09T08:17:50.299Z

Updated: 2026-09-09T20:51:32.253Z

Reserved: 2026-07-20T09:36:53.438Z

Link: CVE-2026-16272

cve-icon Vulnrichment

Updated: 2026-09-09T20:45:56.978Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T09:17:10.720

Modified: 2026-09-09T21:17:01.423

Link: CVE-2026-16272

cve-icon Redhat

No data.