CVE-2026-82211: Unknown Nexi Xpay Build
High severity, CVSS 8.2. EPSS: 0.2% chance of exploitation in the next 30 days.
The Nexi XPay Build WordPress plugin through 7.6.2 does not verify the payment result supplied to several of its unauthenticated routes, allowing attackers to mark arbitrary orders as paid or failed, to cancel them, and to obtain order keys which expose guest buyers' details.
Affected products
- Unknown Nexi Xpay Build: from 7.0.0, up to and including 7.6.2
Published 2026-10-07. Last modified 2026-10-07.