---
id: CVE-2026-16037
title: >-
  Observable timing discrepancy vulnerability in PayTR Payment and Electronic
  Money Institution Inc
summary: >-
  Observable timing discrepancy vulnerability in PayTR Payment and Electronic
  Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows
  Black Box Reverse Engineering.


  This issue affects PayTR Virtual Pos iFrame API (v9…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-208
vendor: PayTR Payment and Electronic Money Institution Inc.
product: PayTR Virtual Pos iFrame API (v9x) WHMCS Module
affected:
  - paytr_virtual_pos_iframe_api_v9x_whmcs_module >= v9.0.0 < v9.0.3
published: '2026-09-08'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T18:34:41.780'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16037'
references:
  - url: 'https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1034'
    label: iletisim@usom.gov.tr
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-08T15:47:06.868632Z'
ingestedAt: '2026-09-08T15:33:26.988Z'
epss: 0.00303
epssPercentile: 0.20418
---

## Overview

Observable timing discrepancy vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Black Box Reverse Engineering.

This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
