Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 3 min 134 bronnen 2 kritiek 4 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2026-82212

HIGH · 7.5 CVSS Gepubliceerd: CWE-345

Beschrijving

The Nexi XPay Build WordPress plugin through 7.6.2 does not correctly validate the security token on its payment notification route, accepting the request when the target order has no stored token, which allows unauthenticated attackers to mark arbitrary orders as paid, or to mark genuinely paid orders as failed.

References