Redpacketsecurity
CVE-2026-16025 and CVE-2026-16037: Vulnerabilities in PayTR Virtual Pos iFrame API
Article Content
Two critical vulnerabilities have been identified in the PayTR Virtual Pos iFrame API (v9x) WHMCS Module, both published on 2026-09-08. CVE-2026-16025 involves improper validation of input quantities, allowing attackers to manipulate transaction data, potentially leading to revenue loss and customer disputes. CVE-2026-16037 features a timing discrepancy vulnerability that could enable black box reverse engineering, undermining payment callback authentication. Both vulnerabilities affect versions from v9.0.0 to before v9.0.3 and pose high risks to internet-facing WHMCS installations, particularly those handling high-value transactions. Currently, there is no evidence of active exploitation for either vulnerability, but they require urgent attention and remediation. Administrators are urged to apply vendor patches and monitor for suspicious activity.
Key Points: • CVE-2026-16025 allows input data manipulation in payment transactions. • CVE-2026-16037 enables black box reverse engineering of payment callbacks. • Both vulnerabilities affect PayTR Virtual Pos iFrame API versions 9.0.0 to 9.0.2.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.