CVE-2026-87791 Details
Description
A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme. The vulnerability allows an unauthenticated attacker to download arbitrary files accessible by the web server process.
A path traversal vulnerability has been identified in the WordPress Design Scuole Italia theme, specifically within the reserved_file_check function in functions.php. This vulnerability allows unauthenticated attackers to download arbitrary files that are accessible by the web server process. The issue arises from inadequate validation of file paths, enabling exploitation by manipulating the requested file path to access sensitive files on the server.
Users are advised to update the WordPress Design Scuole Italia theme to version 2.18.3 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 15, 2026CISA-ADP
Assessed Sep 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/italia/design-scuole-wordpress-theme | ENISA | Source CodeVendor |
| https://www.acn.gov.it/portale/w/rilevate-vulnerabilita-nel-tema-wordpress-design-scuole-italia- | ENISA | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | ENISA |
Affected Products
| Product | Versions |
|---|---|
| Italia Design Scuole Italia | < 2.18.3 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 15, 2026 | CVE Modified | CISA-ADP |
| Sep 15, 2026 | New CVE Received | ENISA |
Volerion