Description
Observable timing discrepancy vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Black Box Reverse Engineering.

This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.
Published: 2026-09-08
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass (Unauthorized Transactions)
Action: Upgrade Module
AI Analysis

Impact

This vulnerability is a timing discrepancy flaw in PayTR's Virtual Pos iFrame API (v9x) WHMCS Module, identified as a CWE-208 (Timing Attack) weakness. An attacker can use observable response times to reverse engineer the authentication process, ultimately bypassing authentication and executing fraudulent financial transactions. The flaw directly compromises transaction integrity and exposes payment processing to unauthorized access.

Affected Systems

PayTR Virtual Pos iFrame API (v9x) WHMCS Module from PayTR Payment and Electronic Money Institution Inc. Versions prior to 9.0.3, starting with 9.0.0, are affected. The vulnerability exists only in the earlier builds and is fixed from 9.0.3 onward.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote, web‑based timing attack against the API endpoint; this inference comes from the use of timing differences in authentication responses. An attacker does not need prior access to the system but must be able to send repeated authentication requests and measure the response delays. Successful exploitation would allow the bypass of authentication, enabling the creation of unauthorized payment records.

Generated by OpenCVE AI on September 8, 2026 at 18:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade PayTR Virtual Pos iFrame API (v9x) WHMCS Module to version 9.0.3 or later.
  • Restrict module accessibility by limiting API access to trusted IP addresses or internal networks.
  • Implement rate limiting or request throttling on the authentication endpoint to reduce the effectiveness of timing measurements.
  • Continuously monitor transaction logs for anomalous authentication patterns or unexpected transaction activity.

Generated by OpenCVE AI on September 8, 2026 at 18:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Paytr
Paytr paytr Virtual Pos Iframe Api (v9x) Whmcs Module
Vendors & Products Paytr
Paytr paytr Virtual Pos Iframe Api (v9x) Whmcs Module

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Observable timing discrepancy vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Black Box Reverse Engineering. This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.
Title Callback Authentication Bypass via Timing Attack in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Module
Weaknesses CWE-208
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Paytr Paytr Virtual Pos Iframe Api (v9x) Whmcs Module
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-08T15:48:16.865Z

Reserved: 2026-07-17T09:10:13.007Z

Link: CVE-2026-16037

cve-icon Vulnrichment

Updated: 2026-09-08T15:48:12.019Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T16:18:01.997

Modified: 2026-09-08T18:34:41.780

Link: CVE-2026-16037

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:34:50Z

Weaknesses
  • CWE-208

    Observable Timing Discrepancy