Sceawere

Vulnerability Detail

CVE-2026-82211UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Nexi XPay Improper Access Control

Vulnerability Metadata

Severity
High
Score / CVSS
8.2
Creation Date
3h ago
Vendor
Unknown
Product
Nexi XPay Build
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Nexi XPay Build WordPress plugin through 7.6.2 does not verify the payment result supplied to several of its unauthenticated routes, allowing attackers to mark arbitrary orders as paid or failed, to cancel them, and to obtain order keys which expose guest buyers' details.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.2",
  "pubDate": "2026-10-07T07:17:01.373Z",
  "pubdate": "2026-10-07T07:17:01.373Z",
  "executiveSummary": "The Nexi XPay plugin for WordPress, specifically versions through 7.6.2, is affected by an improper access control vulnerability within its unauthenticated API routes. This flaw stems from a lack of server-side verification of payment results provided by external requests.\nAn unauthenticated attacker can exploit this vulnerability to manipulate the state of arbitrary orders within the WooCommerce system. By submitting crafted requests, an adversary can force an order to a 'paid', 'failed', or 'cancelled' status without genuine payment verification.\nFurthermore, the vulnerability allows unauthorized access to sensitive order keys, which can be leveraged to retrieve personal information associated with guest buyers. This poses a significant risk to data confidentiality and integrity, as it enables unauthorized modification of transaction records and potential exposure of customer PII (Personally Identifiable Information).\nThe vulnerability is remotely exploitable and does not require authentication, making it a high-severity concern for e-commerce platforms relying on this payment gateway. Immediate updates are recommended to restore proper transactional integrity.",
  "technicalDetails": "The root cause of the vulnerability lies in the improper implementation of callback or notification handler functions within the Nexi XPay plugin's unauthenticated API endpoints. The plugin exposes specific network-accessible routes designed to receive payment notifications from the Nexi XPay gateway. However, these endpoints fail to cryptographically verify or perform a server-to-server validation (such as a signature check or a status inquiry to the payment provider) before processing the incoming payment result.\nBecause the plugin trusts the integrity of the data supplied in the request body without secondary validation, an attacker can perform a direct HTTP POST request to these endpoints. By manipulating the order ID and the status parameter within the payload, the attacker can effectively 'spoof' a successful payment callback.\nThe attack flow proceeds as follows: First, the attacker identifies a target order ID within the WordPress instance. Second, the attacker sends a specially crafted HTTP request to the vulnerable Nexi XPay endpoint. Third, the plugin's internal logic processes the input, validates that the order exists, and transitions the WooCommerce order object to the status specified by the attacker (e.g., 'wc-completed'). Finally, the plugin may inadvertently disclose associated order keys or metadata during the response cycle or due to exposed endpoints, allowing the attacker to retrieve the guest buyer's details linked to that order.\nThis vulnerability exists in versions through 7.6.2. The lack of an authentication requirement means that any remote user can interact with these endpoints via standard web protocols. The primary risk factor is the bypass of the payment gateway's secure verification mechanism, allowing attackers to perform 'payment spoofing'. This bypass effectively tricks the e-commerce platform into fulfilling orders that were never paid for by the customer, resulting in financial loss and potential unauthorized access to sensitive customer order data.\nThe exposure of order keys further exacerbates the impact, as it circumvents standard access controls that typically protect private order pages, allowing an attacker to scrape private guest information."
}
CVE-2026-82211: Nexi XPay Improper Access Control (HIGH Severity, CVSS: 8.2) | Sceawere