Retour à la veille

CVE-2026-82211

Publié : 7 octobre 2026
Modifié : 7 octobre 2026
Lien officiel NVD
Score CVSS
8.2
HIGH

Description détaillée

The Nexi XPay Build WordPress plugin through 7.6.2 does not verify the payment result supplied to several of its unauthenticated routes, allowing attackers to mark arbitrary orders as paid or failed, to cancel them, and to obtain order keys which expose guest buyers' details.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N

Références et Patchs