CVE-2026-16037: Callback Authentication Bypass via Timing Attack in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Module
Observable timing discrepancy vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Black Box Reverse Engineering.
This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.
Affected Software
Event History
Frequently Asked Questions
Which versions require remediation?
The issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module versions from v9.0.0 up to, but not including, v9.0.3. Updating to v9.0.3 or later removes the affected version range.
Does exploitation require authentication or user interaction?
No. The supplied CVSS vector indicates network access, low attack complexity, no privileges required, and no user interaction required.
What is the expected impact if exploited?
The vulnerability is associated with callback authentication bypass through an observable timing discrepancy and is rated high severity with a 7.5 CVSS score. The vector indicates high confidentiality impact, with no integrity or availability impact stated.