PT-2026-88898 · Paytr Payment Electronic Money Institution · Paytr Virtual Pos Iframe Api (V9X) Whmcs Module

·

CVE-2026-16272

·

Published

2026-09-09

·

Updated

2026-09-09

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Exploitation of Trusted Identifiers.
This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16272

Affected Products

Paytr Virtual Pos Iframe Api (V9X) Whmcs Module