CVE-2026-87792

Summary

The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions, allowing an unauthenticated attacker to access restricted "Circolare" content and registered users' data. An unauthenticated RSS feed at /circolare/feed/ further facilitates exploitation.

Affected Software

VendorProductVersion RangeStatus
Developers Italiadesign-scuole-wordpress-theme1.0 <= 2.17.3affected

Weaknesses

  • CWE-862: CWE-862
  • CWE-200: CWE-200

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References