Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. (CVE-2026-16272)
A critical vulnerability (CVE-2026-16272) exists in the PayTR Virtual Pos iFrame API (v9x) WHMCS Module that allows exploitation of trusted identifiers due to use of less trusted sources. This affects versions from 9.0.0 up to but not including 9.0.3. The vulnerability has a high CVSS score of 9.1, indicating it can be exploited remotely without privileges or user interaction, leading to high confidentiality and integrity impact.
AI Analysis
Technical Summary
CVE-2026-16272 is a use of less trusted source vulnerability (CWE-348) in the PayTR Virtual Pos iFrame API (v9x) WHMCS Module. It allows attackers to exploit trusted identifiers by leveraging less trusted sources, potentially compromising the trust model of the payment integration. The affected versions are from 9.0.0 before 9.0.3. The vulnerability has a CVSS 3.1 base score of 9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N), indicating remote exploitability without authentication or user interaction, resulting in high confidentiality and integrity impact but no availability impact. No known exploits in the wild or patch information is currently provided.
Potential Impact
An attacker can remotely exploit this vulnerability without authentication or user interaction to compromise the confidentiality and integrity of the payment system by exploiting trusted identifiers. This could lead to unauthorized transactions or manipulation of payment data. There is no impact on availability reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are currently provided. Until a patch is available, closely monitor vendor communications for updates. Avoid deploying affected versions in sensitive environments if possible.
Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. (CVE-2026-16272)
Description
A critical vulnerability (CVE-2026-16272) exists in the PayTR Virtual Pos iFrame API (v9x) WHMCS Module that allows exploitation of trusted identifiers due to use of less trusted sources. This affects versions from 9.0.0 up to but not including 9.0.3. The vulnerability has a high CVSS score of 9.1, indicating it can be exploited remotely without privileges or user interaction, leading to high confidentiality and integrity impact.
CVSS v3.1
Score 9.1critical
Affected software
pkg:github/paytr/whmcs-moduleRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-16272 is a use of less trusted source vulnerability (CWE-348) in the PayTR Virtual Pos iFrame API (v9x) WHMCS Module. It allows attackers to exploit trusted identifiers by leveraging less trusted sources, potentially compromising the trust model of the payment integration. The affected versions are from 9.0.0 before 9.0.3. The vulnerability has a CVSS 3.1 base score of 9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N), indicating remote exploitability without authentication or user interaction, resulting in high confidentiality and integrity impact but no availability impact. No known exploits in the wild or patch information is currently provided.
Potential Impact
An attacker can remotely exploit this vulnerability without authentication or user interaction to compromise the confidentiality and integrity of the payment system by exploiting trusted identifiers. This could lead to unauthorized transactions or manipulation of payment data. There is no impact on availability reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are currently provided. Until a patch is available, closely monitor vendor communications for updates. Avoid deploying affected versions in sensitive environments if possible.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-g622-qgc4-8v95
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-16272"]
- Ecosystems
- []
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
Threat ID: 6aa15f6bacd9273b49618021
Added to database: 09/09/2026, 13:30:19 UTC
Last enriched: 09/09/2026, 14:24:24 UTC
Last updated: 09/09/2026, 22:52:09 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.