CVE-2026-82211: Nexi XPay Build <= 7.6.2 - Unauthenticated Payment Completion and Order Key Disclosure
The Nexi XPay Build WordPress plugin through 7.6.2 does not verify the payment result supplied to several of its unauthenticated routes, allowing attackers to mark arbitrary orders as paid or failed, to cancel them, and to obtain order keys which expose guest buyers' details.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
No authentication or user interaction is required. The affected routes are unauthenticated and do not verify the supplied payment result.
What can an attacker do to orders?
An attacker can mark arbitrary orders as paid or failed, or cancel them. This can compromise order integrity without requiring access to a WordPress account.
What information could be exposed?
Attackers can obtain order keys, which expose guest buyers' details. The provided data does not specify which individual buyer details are included.
Which plugin versions are affected?
Nexi XPay Build WordPress plugin versions through 7.6.2 are affected. The provided data does not identify a fixed version or workaround.