Nexi XPay <= 8.3.1 - Missing Authorization
medium
The Nexi XPay plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 8.3.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 8.3.1
- Fixed in:
- 8.3.2
- Disclosed:
- Jun 17, 2026
CVE-2026-54810 on NVD →
Nexi XPay <= 8.3.0 - Missing Authorization to Unauthenticated Order Status Modification
medium
The Nexi XPay plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization checks on the redirect function in all versions up to, and including, 8.3.0. This makes it possible for unauthenticated attackers to mark pending WooCommerce orders as paid/completed.
- CVSS:
- 5.3
- Affected:
- up to 8.3.0
- Fixed in:
- 8.3.2
- Disclosed:
- Apr 14, 2026
CVE-2025-15565 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database