Executive brief
The Nexi XPay Build WordPress plugin, used to accept payments via the Nexi payment gateway in WooCommerce stores, fails to verify that payment tokens belong to the requesting user. An attacker can enumerate and retrieve other customers' stored credit card token references and valid authorization signatures without authentication, exposing payment method details across the entire store.
Technical details
The plugin contains an insecure direct object reference (IDOR) vulnerability in the build_payment_payload AJAX action. The vulnerability exists because the token_id parameter is not validated to ensure it belongs to the currently logged-in user, and no authentication check is enforced. An unauthenticated attacker can enumerate sequential token identifiers (1, 2, 3, etc.) to discover all saved payment tokens in the store and retrieve each token's reference, transaction code, timestamp, and server-signed authorization signature. The attacker can craft requests using their own cart amount, meaning the signed payload is valid for any transaction value they choose. The plugin applies no gateway filter, so tokens saved for different payment methods are all disclosed equally.
Affected products
- Nexi XPay Build 7.6.1–7.6.2
Timeline
- 2026-09-08: disclosed
- 2026-09-11: advisory