Authorization Bypass Vulnerabilities in Design Scuole Italia WordPress Theme
CVE-2026-87792

8.7HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 September 2026

What is CVE-2026-87792?

The Design Scuole Italia WordPress theme suffers from multiple Authorization Bypass vulnerabilities in its dsi_pdf_generator and dsi_csv_generator functions. These vulnerabilities enable unauthenticated attackers to gain access to sensitive 'Circolare' content and data associated with registered users. Additionally, an unauthenticated RSS feed located at /circolare/feed/ simplifies the exploitation of these vulnerabilities, increasing the potential for unauthorized data exposure.

Affected Version(s)

design-scuole-wordpress-theme 1.0 <= 2.17.3

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Filippo Sorbellini
CSIRT-IT
.