Sceawere
Vulnerability Detail
CVE-2026-82212UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Nexi XPay Improper Access Control
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- Unknown
- Product
- Nexi XPay Build
- Attack Type
- CWE-345 Insufficient Verification of Data Authenticity
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Nexi XPay Build WordPress plugin through 7.6.2 does not correctly validate the security token on its payment notification route, accepting the request when the target order has no stored token, which allows unauthenticated attackers to mark arbitrary orders as paid, or to mark genuinely paid orders as failed.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-07T07:17:01.493Z",
"pubdate": "2026-10-07T07:17:01.493Z",
"executiveSummary": "The Nexi XPay Build WordPress plugin, in versions through 7.6.2, is affected by an improper access control vulnerability within its payment notification processing logic.\nThe vulnerability stems from an insecure validation mechanism regarding security tokens on the payment notification route. When a target order lacks a stored security token, the system incorrectly defaults to accepting the incoming request.\nThis flaw allows unauthenticated remote attackers to manipulate order statuses by interacting directly with the plugin's notification endpoint. Impacted systems face critical risks, including the potential for unauthorized payment confirmation (fraud) or the malicious invalidation of legitimate transactions.\nThe vulnerability does not require authentication or elevated privileges, making it a high-risk vector for malicious actors targeting e-commerce integrity. Attackers can facilitate financial discrepancies by manipulating the internal state of WooCommerce orders without performing an actual payment transaction.",
"technicalDetails": "The root cause of this vulnerability lies in the improper implementation of the security token verification logic within the payment notification endpoint of the Nexi XPay Build plugin. Specifically, the plugin's verification routine fails to enforce strict authentication when a transaction order identifier does not have a corresponding, pre-existing security token configured in the database.\nIn a secure implementation, the payment notification route is expected to validate an incoming request against a unique, cryptographically secure token provided by the payment gateway to ensure that only legitimate notifications from Nexi are processed. However, in the affected versions, the code path handles the absence of a stored token as a bypass condition rather than a failure state. This logic error allows an attacker to submit crafted HTTP requests to the notification endpoint, which the application then processes as authenticated notifications.\nThe attack flow proceeds as follows: First, an attacker identifies the publicly accessible notification URL of the Nexi XPay plugin. Second, the attacker probes the system by targeting specific order IDs that have not yet been assigned a valid payment token. Third, because the plugin fails to reject requests when the token is missing, the attacker sends a specially crafted notification payload that mimics the structure of a successful payment callback. Finally, the plugin processes this payload, updating the order status in the underlying database to 'paid' or, conversely, 'failed' depending on the content of the manipulated request.\nBecause this endpoint is exposed via the WordPress REST API or equivalent public-facing hooks, it requires no prior authentication or administrative privileges to invoke. An attacker can systematically iterate through sequential order IDs, marking unauthorized orders as 'paid' to circumvent the payment gateway entirely, or disrupting operations by marking active, paid orders as 'failed'. This vulnerability bypasses the plugin’s integrity checks, providing an attacker with an arbitrary level of control over the order fulfillment lifecycle within the WooCommerce environment. The flaw remains present in all versions up to and including 7.6.2, and constitutes a critical failure in the handling of server-to-server payment notifications."
}