---
id: CVE-2026-82212
title: >-
  The Nexi XPay Build WordPress plugin through 7.6.2 does not correctly validate
  the security token on its payment notification route, accepting the request
  when the target order has no stored token, which allows unauthenticated
  attackers …
summary: >-
  The Nexi XPay Build WordPress plugin through 7.6.2 does not correctly validate
  the security token on its payment notification route, accepting the request
  when the target order has no stored token, which allows unauthenticated
  attackers …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-345
product: Nexi XPay Build
affected:
  - nexi_xpay_build >= 7.2.2 <= 7.6.2
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T14:52:43.420'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82212'
references:
  - url: 'https://wpscan.com/vulnerability/66df6adb-336c-4660-9a63-5e6e550a2edb/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-10-07T09:47:29.738476Z'
ingestedAt: '2026-10-07T08:20:03.942Z'
---

## Overview

The Nexi XPay Build WordPress plugin through 7.6.2 does not correctly validate the security token on its payment notification route, accepting the request when the target order has no stored token, which allows unauthenticated attackers to mark arbitrary orders as paid, or to mark genuinely paid orders as failed.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
