The Nexi XPay Build WordPress plugin through 7.6.2 does not verify the payment result supplied to several of its unauthenticated routes, allowing attackers to mark arbitrary orders as paid or failed, to cancel them, and to obtain order keys which expose guest buyers' details.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 07 Oct 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Nexi XPay Build WordPress plugin through 7.6.2 does not verify the payment result supplied to several of its unauthenticated routes, allowing attackers to mark arbitrary orders as paid or failed, to cancel them, and to obtain order keys which expose guest buyers' details. | |
| Title | Nexi XPay Build <= 7.6.2 - Unauthenticated Payment Completion and Order Key Disclosure | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-07T06:47:53.228Z
Reserved: 2026-08-28T08:30:56.950Z
Link: CVE-2026-82211
No data.
Status : Received
Published: 2026-10-07T07:17:01.373
Modified: 2026-10-07T07:17:01.373
Link: CVE-2026-82211
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.