Reflected XSS Vulnerability in Design Scuole Italia WordPress Theme
CVE-2026-87793
5.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 September 2026
What is CVE-2026-87793?
The Design Scuole Italia WordPress theme contains a Reflected XSS vulnerability located in the filters-scheda-didattica.php file. This flaw permits an unauthenticated attacker to execute arbitrary JavaScript in a victim's browser through a specially crafted URL that includes a malicious archive parameter. This vulnerability poses a serious risk, allowing attackers to perform various malicious actions on behalf of the user, including stealing sensitive information or redirecting them to harmful websites.
Affected Version(s)
design-scuole-wordpress-theme 1.0 <= 2.18.2