CVE-2026-16025: Improper Payment Validation in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Module
Improper validation of specified quantity in input vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Input Data Manipulation.
This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.
Affected Software
Event History
Frequently Asked Questions
Which versions require remediation?
The issue affects the PayTR Virtual Pos iFrame API (v9x) WHMCS Module from version 9.0.0 up to, but not including, 9.0.3. Version 9.0.3 or later is not identified as affected by the supplied data.
Does exploitation require authentication or user interaction?
No. The supplied vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
What is the likely security impact?
The stated impact is input data manipulation through improper validation of a specified quantity. The CVSS vector assigns high availability impact, while confidentiality and integrity impacts are listed as none.