Description
The Nexi XPay Build WordPress plugin through 7.6.2 does not verify the payment result supplied to several of its unauthenticated routes, allowing attackers to mark arbitrary orders as paid or failed, to cancel them, and to obtain order keys which expose guest buyers' details.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 07 Oct 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Nexi XPay Build WordPress plugin through 7.6.2 does not verify the payment result supplied to several of its unauthenticated routes, allowing attackers to mark arbitrary orders as paid or failed, to cancel them, and to obtain order keys which expose guest buyers' details. | |
| Title | Nexi XPay Build <= 7.6.2 - Unauthenticated Payment Completion and Order Key Disclosure | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-07T06:47:53.228Z
Reserved: 2026-08-28T08:30:56.950Z
Link: CVE-2026-82211
No data.
Status : Received
Published: 2026-10-07T07:17:01.373
Modified: 2026-10-07T07:17:01.373
Link: CVE-2026-82211
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.