CVE-2026-87791 PUBLISHED

Path traversal vulnerability in WordPress theme design-scuole-wordpress-theme

Assigner: ENISA
Reserved: 09.09.2026 Published: 15.09.2026 Updated: 15.09.2026

A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme. The vulnerability allows an unauthenticated attacker to download arbitrary files accessible by the web server process.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Developers Italia
Product design-scuole-wordpress-theme
Versions Default: unaffected
  • affected from 2.6.0 to 2.18.1 (incl.)

Solutions

Update to version 2.18.2

Credits

  • Filippo Sorbellini finder
  • CSIRT-IT coordinator

References

Problem Types

  • CWE-22 CWE

Impacts

  • CAPEC-126 Path Traversal