Skip to main content

Threat intelligence

Nexi XPay <= 8.3.0 - Missing Authorization to Unauthenticated Order Status Modification

CVE-2025-15565 · cartasi-x-pay

Important: Seeing this vulnerability listed does not mean your website is affected. Exposure depends on whether you run Cartasi X Pay at a vulnerable version. How SiteRespond intelligence works

Vulnerability
Nexi XPay <= 8.3.0 - Missing Authorization to Unauthenticated Order Status Modification
Affected software
cartasi-x-pay(Plugin)
Affected versions
  • ≤ 8.3.0
Authentication
Unauthenticated
Vulnerability type
Other
Published
14 April 2026
CISA KEV
Not listed in CISA KEV at last catalog refresh
Impact
This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.
Source

Data imported from Wordfence Intelligence (advisory f420151b-c783-49b1-b0e9-e936a904278a). Methodology and redistribution notes

Check whether your installed version is affected

SiteRespond Defence matches your installed Cartasi X Pay version against this catalog when the Defence plugin is connected to your WordPress site.