SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-16272

CRITICAL · CVSS 9.1 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The PayTR Virtual Pos iFrame API (v9x) WHMCS Module versions prior to 9.0.3 are vulnerable due to the use of less trusted sources, which allows attackers to exploit trusted identifiers. This critical vulnerability could lead to unauthorized access and manipulation of payment processes, posing significant risks to financial transactions. Organizations utilizing this module should prioritize immediate updates to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-16272
Severity
CRITICAL
CVSS
9.1
EPSS
0.14%

Original NVD Description

Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Exploitation of Trusted Identifiers. This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.