Critical severity9.1NVD Advisory· Published Sep 9, 2026
CVE-2026-16272
CVE-2026-16272
Description
Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Exploitation of Trusted Identifiers.
This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.
Affected products
1- PayTR Payment And Electronic Money Institution Inc./PayTR Virtual Pos iFrame API (v9x) WHMCS Modulellm-fuzzyRange: v9.0.0 <= v < 9.0.3
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.