WordPress security changelog
MEDIUM CVE-2026-82213 Deferred

Nexi XPay Build exposes other customers' saved payment tokens

Nexi XPay Build versions 7.6.1 through 7.6.2 do not verify that a requested saved payment token belongs to the current user. An unauthenticated attacker can retrieve another customer's stored card-token reference together with a valid authorization signature. The authoritative export does not identify the endpoint, token identifier parameter, customer binding, or signing function.

CVE / CNA score 5.3 CVSS 3.1 · contact@wpscan.com
NVD score Pending NVD has not published its own CVSS assessment.
Component
Nexi XPay Build
Plugin slug
nexi-xpay-build
Affected
7.6.1 through 7.6.2
Safe version
See mitigation notes
Published
Sep 11, 2026
Weakness
CWE-639 — Authorization Bypass Through User-Controlled Key

This CVE was published Sep 11, 2026 and is one of 1 known issue for this plugin.

Update, patch or deactivate.

The authoritative export does not identify a fixed release. Obtain a vendor-confirmed remediation and ensure the token lookup requires authentication, verifies ownership server-side, and never returns a reusable authorization signature for another customer's token. Review payment-provider logs if token references may have been exposed.

No confirmed safe version is listed. Consider a vendor-supported patch or temporarily restricting the affected functionality while you assess the risk.

Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.

Technical description

The Nexi XPay Build WordPress plugin from 7.6.1 to 7.6.2 does not verify that the saved payment token being requested belongs to the current user, allowing unauthenticated attackers to retrieve other customers' stored card token references together with a valid authorisation signature.

CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Primary and upstream sources