← WordPress Vulnerabilities
WordPress security by component

Nexi XPay Build

Nexi XPay Build (nexi-xpay-build) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 5.3.

Plugin slug: nexi-xpay-build

CVE-2026-82213: Nexi XPay Build exposes other customers' saved payment tokens

Nexi XPay Build versions 7.6.1 through 7.6.2 do not verify that a requested saved payment token belongs to the current user. An unauthenticated attacker can retrieve another customer's stored card-token reference together with a valid authorization signature. The authoritative export does not identify the endpoint, token identifier parameter, customer binding, or signing function.

PublishedSep 11, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for nexi-xpay-build
Safe version
Sep 11, 2026 CVE-2026-82213
Nexi XPay Build exposes other customers' saved payment tokens
Nexi XPay Build versions 7.6.1 through 7.6.2 do not verify that a requested saved payment token belongs to the current user. An unauthenticated attacker can retrieve another customer's stored card-token reference together with a valid authorization signature. The authoritative export does not identify the endpoint, token identifier parameter, customer binding, or signing function.
See mitigation notes
CVE5.3
NVDPending