CVE-2025-15565 PUBLISHED

Nexi XPay <= 8.3.0 - Missing Authorization to Unauthenticated Order Status Modification

Assigner: Wordfence
Reserved: 05.02.2026 Published: 14.04.2026 Updated: 15.04.2026

The Nexi XPay plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization checks on the redirect function in all versions up to, and including, 8.3.0. This makes it possible for unauthenticated attackers to mark pending WooCommerce orders as paid/completed.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS Score: 5.3

Product Status

Vendor cartasi
Product Nexi XPay
Versions Default: unaffected
  • affected from 0 to 8.3.0 (incl.)

Credits

  • Md. Moniruzzaman Prodhan finder

References

Problem Types

  • CWE-862 Missing Authorization CWE