Junglewise Threat Intelligence

CVE-2026-54810: Nexi Payments Nexi XPay missing authorization in WordPress plugin

CVE-2026-54810 · Severity: high · CVSS 7.5 · Published 2026-06-17

Executive brief

Nexi XPay is a WordPress plugin used to integrate payment processing services into websites. A security flaw in the plugin allows unauthorized individuals to bypass access controls due to incorrectly configured security levels. This could potentially allow attackers to disrupt payment services or perform administrative actions without permission, impacting the site's ability to process transactions.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Nexi XPay plugin for WordPress through version 8.3.1. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before executing sensitive functions. An unauthenticated remote attacker can exploit this vulnerability over the network without any user interaction. According to the CVSS vector, the primary technical impact is on availability, potentially allowing an attacker to disrupt the plugin's functionality. A fix is available in version 8.3.2.

Affected products

  • Nexi Payments Nexi XPay <= 8.3.1

Timeline

  • 2026-02-19: disclosed: Reported by hivesec
  • 2026-06-17: advisory: Published by Patchstack and NVD
  • 2026-06-17: patched: Version 8.3.2 released to address the vulnerability

References