Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-82213

MEDIUM NVD
CVSS Score 5.3
Severity MEDIUM
Published Sep 11, 2026
Vendor unknown

Description

The Nexi XPay Build WordPress plugin from 7.6.1 to 7.6.2 does not verify that the saved payment token being requested belongs to the current user, allowing unauthenticated attackers to retrieve other customers' stored card token references together with a valid authorisation signature.

References