---
id: CVE-2026-82213
title: >-
  The Nexi XPay Build WordPress plugin from 7.6.1 to 7.6.2 does not verify that
  the saved payment token being requested belongs to the current user, allowing
  unauthenticated attackers to retrieve other customers' stored card token
  referenc…
summary: >-
  The Nexi XPay Build WordPress plugin from 7.6.1 to 7.6.2 does not verify that
  the saved payment token being requested belongs to the current user, allowing
  unauthenticated attackers to retrieve other customers' stored card token
  referenc…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-639
product: Nexi XPay Build
affected:
  - nexi_xpay_build >= 7.6.1 <= 7.6.2
published: '2026-09-11'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T17:35:21.440'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82213'
references:
  - url: 'https://wpscan.com/vulnerability/ccdf87ac-7442-441f-ad96-466c715b1d66/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-11T12:05:32.819943Z'
ingestedAt: '2026-09-11T16:45:47.922Z'
epss: 0.00323
epssPercentile: 0.22676
---

## Overview

The Nexi XPay Build WordPress plugin from 7.6.1 to 7.6.2 does not verify that the saved payment token being requested belongs to the current user, allowing unauthenticated attackers to retrieve other customers' stored card token references together with a valid authorisation signature.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
