CVE-2026-82213 PUBLISHED

Nexi XPay Build 7.6.1 - 7.6.2 - Unauthenticated Saved Payment Token Disclosure via IDOR

Assigner: WPScan
Reserved: 28.08.2026 Published: 11.09.2026 Updated: 11.09.2026

The Nexi XPay Build WordPress plugin from 7.6.1 to 7.6.2 does not verify that the saved payment token being requested belongs to the current user, allowing unauthenticated attackers to retrieve other customers' stored card token references together with a valid authorisation signature.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 5.3

Product Status

Vendor Unknown
Product Nexi XPay Build
Versions Default: unknown
  • affected from 7.6.1 to 7.6.2 (incl.)

Credits

  • ryan fabella finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE