Skip to main content
Vulnerability Database/CVE-2026-82211

CVE-2026-82211: Nexi XPay Build WordPress Auth Bypass

CVE-2026-82211 is an authentication bypass flaw in Nexi XPay Build WordPress plugin allowing attackers to manipulate payment results and access customer data. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-82211 Overview

The Nexi XPay Build WordPress plugin through version 7.6.2 contains a missing authorization vulnerability [CWE-862]. Several unauthenticated routes accept payment result values from the client without server-side verification. Attackers can mark arbitrary orders as paid or failed, cancel orders, and retrieve order keys that expose guest buyer details. The flaw affects the plugin's payment callback handling and impacts e-commerce sites processing transactions through the Nexi XPay gateway.

Critical Impact

Unauthenticated attackers can manipulate order payment states and exfiltrate guest buyer information from WooCommerce stores using the plugin.

Affected Products

  • Nexi XPay Build WordPress plugin versions up to and including 7.6.2
  • WooCommerce stores integrating the Nexi XPay payment gateway
  • WordPress sites exposing the vulnerable unauthenticated plugin routes

Discovery Timeline

  • 2026-10-07 - CVE-2026-82211 published to NVD
  • 2026-10-07 - Last updated in NVD database

Technical Details for CVE-2026-82211

Vulnerability Analysis

The plugin exposes several unauthenticated endpoints that process payment result data supplied by the client. Instead of validating payment outcomes server-side against the Nexi payment processor, the routes trust the values provided in the request. An attacker can call these endpoints without authentication and declare that an arbitrary order has been paid, has failed, or should be cancelled.

The vulnerability also allows retrieval of order keys through the same unauthenticated interface. Order keys in WooCommerce grant access to guest order detail pages, exposing buyer names, addresses, email addresses, and purchased items. The flaw combines broken access control with trust in client-supplied state, producing both integrity and confidentiality impact.

Root Cause

The root cause is missing authorization and absent server-side verification of payment results [CWE-862]. The plugin's callback and status-handling routes do not perform capability checks, nonce validation, or signature verification against the Nexi gateway before mutating order state. Any request reaching the endpoints is processed as authoritative.

Attack Vector

Exploitation requires only network access to the vulnerable WordPress site. The attacker sends crafted HTTP requests to the plugin's public routes, specifying a target order identifier and the desired payment outcome. No user interaction or privileges are required. The attacker can iterate order identifiers to enumerate guest orders and harvest order keys. See the WPScan Vulnerability Report for route-level details.

Detection Methods for CVE-2026-82211

Indicators of Compromise

  • Unauthenticated HTTP requests to Nexi XPay plugin callback endpoints from non-Nexi source IP addresses
  • Unexpected order state transitions in WooCommerce logs (orders flipping to paid, failed, or cancelled without a corresponding gateway transaction)
  • Access log entries requesting order detail pages with valid order-key parameters shortly after plugin endpoint calls

Detection Strategies

  • Correlate WooCommerce order status change events against authenticated gateway transaction records from Nexi
  • Alert on bursts of requests to plugin routes containing sequential or enumerated order identifiers
  • Flag HTTP requests to the plugin's unauthenticated routes that originate outside the published Nexi IP ranges

Monitoring Recommendations

  • Enable verbose WooCommerce logging to capture status transitions, actor, and request source
  • Forward WordPress and web server logs to a centralized analytics platform for pattern analysis
  • Monitor outbound notifications (order confirmation emails, inventory decrements) for anomalies tied to fraudulent state changes

How to Mitigate CVE-2026-82211

Immediate Actions Required

  • Update the Nexi XPay Build plugin to a version later than 7.6.2 once the vendor publishes a fix
  • Audit recent order activity for suspicious state transitions and reconcile against Nexi gateway records
  • Rotate exposed order keys and notify affected guest buyers if data access is confirmed

Patch Information

At the time of publication, no fixed version is referenced in the NVD entry. Monitor the WPScan Vulnerability Report and the vendor's plugin changelog for an updated release that enforces server-side verification of payment results.

Workarounds

  • Restrict access to the plugin's callback endpoints at the web server or WAF layer, allowing only Nexi gateway source IP ranges
  • Disable or deactivate the plugin on sites that are not actively processing Nexi XPay transactions
  • Add web application firewall rules that block unauthenticated requests attempting to modify order state parameters
bash
# Example nginx restriction limiting plugin callback routes to Nexi source ranges
location ~* /wp-content/plugins/nexi-xpay-build/ {
    allow  <nexi_gateway_cidr>;
    deny   all;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.