Nexi XPay Build WordPress 插件 7.6.2 及以下版本在其支付通知路由中未能正确验证安全令牌。当目标订单没有存储的安全令牌时,该插件仍会接受请求,这使得未经身份验证的攻击者可以将任意订单标记为已支付,或已将实际已支付的订单标记为失败。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Nexi XPay Build | 7.2.2≤ 7.6.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Nexi XPay Build | 7.2.2 ~ 7.6.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82211 | 8.2 HIGH | Nexi XPay Build <= 7.6.2 - Unauthenticated Payment Completion and Order Key Disclosure |
| CVE-2026-86833 | 5.4 MEDIUM | MetForm < 4.3.1 - Unauthenticated HTML Injection in Notification Emails via Field Shortcod |
| CVE-2026-105322 | 5.3 MEDIUM | Magee Shortcodes <= 2.1.1 - Unauthenticated Mail Relay via Contact Form |
| CVE-2026-103323 | Integration for Epos Now and WooCommerce 4.6.0 - 4.11.1 - Unauthenticated Action Scheduler | |
| CVE-2026-104049 | Academy LMS < 4.0.0 - Subscriber+ Arbitrary Lesson Content Disclosure via Topic REST Endpo | |
| CVE-2026-104651 | Yaad Sarig Payment Gateway For WC < 2.2.13 - Subscriber+ Arbitrary Order Payment Manipulat | |
| CVE-2026-104652 | Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Image ID | |
| CVE-2026-104050 | Academy LMS < 4.0.0 - Subscriber+ Cross-Course Quiz Answer Disclosure via render_quiz_answ | |
| CVE-2026-103681 | Frontend Dashboard < 3.0.0 - Subscriber+ Profile and Post Field Deletion via fed_user_prof | |
| CVE-2026-103378 | Geliver Akıllı Kargo Pazaryeri 3.0.0 - 3.1.0 - Unauthenticated API Key Disclosure via Publ | |
| CVE-2026-104653 | Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Crop Dimensions | |
| CVE-2026-104953 | MPG < 4.2.3 - Editor+ SQLi via Project Import | |
| CVE-2026-104677 | WP Coder 4.0 - 4.5.1 - Editor+ RCE via Global PHP | |
| CVE-2026-104667 | Animated Number Counters < 3.1 - Editor+ Second-Order SQLi via Counter Order | |
| CVE-2026-104678 | CP Media Player < 1.3.4 - Contributor+ Media Player Settings Update | |
| CVE-2026-105316 | Magee Shortcodes <= 2.1.1 - Reflected XSS via live_preview and magee_create_shortcode Acti | |
| CVE-2026-86816 | WPCafe < 3.0.21 - Unauthenticated Product Data Disclosure via REST API | |
| CVE-2026-87971 | If-So Dynamic Content 1.4.4 - 1.10.1 - Reflected XSS via 'message' Parameter | |
| CVE-2026-87782 | Koinonia Link 1.1.2 - 1.1.4 - Subscriber+ Privilege Escalation to Administrator | |
| CVE-2026-97188 | String Locator < 2.6.8 - Unauthenticated PHP Object Injection via Database Editor |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet