Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| Metrics |
ssvc
|
Wed, 07 Oct 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 CWE-640 |
Wed, 07 Oct 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Nexi XPay Build WordPress plugin through 7.6.2 does not verify the payment result supplied to several of its unauthenticated routes, allowing attackers to mark arbitrary orders as paid or failed, to cancel them, and to obtain order keys which expose guest buyers' details. | |
| Title | Nexi XPay Build <= 7.6.2 - Unauthenticated Payment Completion and Order Key Disclosure | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-07T09:48:41.823Z
Reserved: 2026-08-28T08:30:56.950Z
Link: CVE-2026-82211
Updated: 2026-10-07T09:48:37.990Z
Status : Deferred
Published: 2026-10-07T07:17:01.373
Modified: 2026-10-07T14:52:43.420
Link: CVE-2026-82211
No data.
OpenCVE Enrichment
Updated: 2026-10-07T11:30:16Z