---
id: CVE-2026-82211
title: >-
  The Nexi XPay Build WordPress plugin through 7.6.2 does not verify the payment
  result supplied to several of its unauthenticated routes, allowing attackers
  to mark arbitrary orders as paid or failed, to cancel them, and to obtain
  order k…
summary: >-
  The Nexi XPay Build WordPress plugin through 7.6.2 does not verify the payment
  result supplied to several of its unauthenticated routes, allowing attackers
  to mark arbitrary orders as paid or failed, to cancel them, and to obtain
  order k…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'
cwe:
  - CWE-862
product: Nexi XPay Build
affected:
  - nexi_xpay_build >= 7.0.0 <= 7.6.2
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T10:17:36.210'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82211'
references:
  - url: 'https://wpscan.com/vulnerability/c1ab38b4-2445-4a56-a47e-aab2b8e8de1e/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-10-07T09:47:59.836401Z'
ingestedAt: '2026-10-07T08:20:03.941Z'
---

## Overview

The Nexi XPay Build WordPress plugin through 7.6.2 does not verify the payment result supplied to several of its unauthenticated routes, allowing attackers to mark arbitrary orders as paid or failed, to cancel them, and to obtain order keys which expose guest buyers' details.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
