← voltar
CVE-2026-82212highCWE-345

Nexi XPay Build <= 7.6.2 - Unauthenticated Payment Bypass via NPG Notification Handler

18Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 7.5
probabilidade de exploração
—
exploração observada
nãonenhuma fonte reporta
The Nexi XPay Build WordPress plugin through 7.6.2 does not correctly validate the security token on its payment notification route, accepting the request when the target order has no stored token, which allows unauthenticated attackers to mark arbitrary orders as paid, or to mark genuinely paid orders as failed.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N