Path Traversal Vulnerability in WordPress Design Scuole Italia Theme
CVE-2026-87791

8.7HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 September 2026

What is CVE-2026-87791?

The reserved_file_check function in the functions.php file of the WordPress Design Scuole Italia theme is susceptible to a path traversal vulnerability. This flaw enables unauthenticated attackers to exploit the system, potentially allowing them to download arbitrary files that the web server can access, thereby compromising the security of sensitive data.

Affected Version(s)

design-scuole-wordpress-theme 2.6.0 <= 2.18.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Filippo Sorbellini
CSIRT-IT
.