Impact
The vulnerability in the Nexi XPay Build WordPress plugin permits an attacker to obtain stored card token references and authorisation signatures belonging to other users without authentication. This type of unauthenticated IDOR enables the disclosure of payment data, compromising user confidentiality and potentially enabling fraud.
Affected Systems
The affected product is the Nexi XPay Build WordPress plugin, specifically versions 7.6.1 through 7.6.2. Users running these versions are at risk of having their payment token information exposed.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the likelihood of exploitation is uncertain but possible. Attackers can leverage unauthenticated HTTP requests to the plugin’s endpoint that does not enforce proper ownership checks, allowing token discovery without needing credentials.
OpenCVE Enrichment