WordPress security by component
Nexi XPay Build
Nexi XPay Build (nexi-xpay-build) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 5.3.
Plugin slug:
nexi-xpay-buildLatest vulnerability
CVE-2026-82213: Nexi XPay Build exposes other customers' saved payment tokens
Nexi XPay Build versions 7.6.1 through 7.6.2 do not verify that a requested saved payment token belongs to the current user. An unauthenticated attacker can retrieve another customer's stored card-token reference together with a valid authorization signature. The authoritative export does not identify the endpoint, token identifier parameter, customer binding, or signing function.
| Safe version |
|
||
|---|---|---|---|
| Sep 11, 2026 |
CVE-2026-82213
Nexi XPay Build exposes other customers' saved payment tokens
Nexi XPay Build versions 7.6.1 through 7.6.2 do not verify that a requested saved payment token belongs to the current user. An unauthenticated attacker can retrieve another customer's stored card-token reference together with a valid authorization signature. The authoritative export does not identify the endpoint, token identifier parameter, customer binding, or signing function.
|
See mitigation notes |
CVE5.3
NVDPending
|