Vulnerability Description
The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions, allowing an unauthenticated attacker to access restricted "Circolare" content and registered users' data. An unauthenticated RSS feed at /circolare/feed/ further facilitates exploitation.
Related Weaknesses (CWE)
References
- https://github.com/italia/design-scuole-wordpress-theme
- https://www.acn.gov.it/portale/w/rilevate-vulnerabilita-nel-tema-wordpress-desig
FAQ
What is CVE-2026-87792?
CVE-2026-87792 is a documented vulnerability. The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions, allowing an unauthenticated attacker t...
How severe is CVE-2026-87792?
CVSS scoring is not yet available for CVE-2026-87792. Check NVD for updates.
Is there a patch for CVE-2026-87792?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.