Description
The Nexi XPay Build WordPress plugin from 7.6.1 to 7.6.2 does not verify that the saved payment token being requested belongs to the current user, allowing unauthenticated attackers to retrieve other customers' stored card token references together with a valid authorisation signature.
Published: 2026-09-11
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Sensitive data disclosure via unauthorized access to payment tokens
Action: Update Plugin
AI Analysis

Impact

The vulnerability in the Nexi XPay Build WordPress plugin permits an attacker to obtain stored card token references and authorisation signatures belonging to other users without authentication. This type of unauthenticated IDOR enables the disclosure of payment data, compromising user confidentiality and potentially enabling fraud.

Affected Systems

The affected product is the Nexi XPay Build WordPress plugin, specifically versions 7.6.1 through 7.6.2. Users running these versions are at risk of having their payment token information exposed.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the likelihood of exploitation is uncertain but possible. Attackers can leverage unauthenticated HTTP requests to the plugin’s endpoint that does not enforce proper ownership checks, allowing token discovery without needing credentials.

Generated by OpenCVE AI on September 11, 2026 at 12:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Nexi XPay Build WordPress plugin to the latest version where this vulnerability is fixed.
  • Disable the plugin or restrict access to authenticated users until a patch is applied.
  • Monitor web traffic for unauthorized requests to the payment token endpoint and audit logs for any unauthorized access.

Generated by OpenCVE AI on September 11, 2026 at 12:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 11 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description The Nexi XPay Build WordPress plugin from 7.6.1 to 7.6.2 does not verify that the saved payment token being requested belongs to the current user, allowing unauthenticated attackers to retrieve other customers' stored card token references together with a valid authorisation signature.
Title Nexi XPay Build 7.6.1 - 7.6.2 - Unauthenticated Saved Payment Token Disclosure via IDOR
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-11T12:07:38.845Z

Reserved: 2026-08-28T08:31:02.009Z

Link: CVE-2026-82213

cve-icon Vulnrichment

Updated: 2026-09-11T12:05:36.691Z

cve-icon NVD

Status : Received

Published: 2026-09-11T11:16:54.957

Modified: 2026-09-11T11:16:54.957

Link: CVE-2026-82213

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T12:30:08Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-639

    Authorization Bypass Through User-Controlled Key