CVE-2026-87793 Details
Description
The "Design Scuole Italia" WordPress theme is affected by a Reflected XSS vulnerability in the filters-scheda-didattica.php file, allowing an unauthenticated attacker to execute arbitrary JavaScript in a victim's browser via a crafted URL containing a malicious archive parameter.
A reflected cross-site scripting vulnerability has been identified in the Design Scuole Italia WordPress theme, specifically in the filters-scheda-didattica.php file. This vulnerability allows an unauthenticated attacker to execute arbitrary JavaScript in a victim's browser. The issue arises from inadequate validation and sanitization of the 'archive' parameter, which is managed by the vulnerable file. An attacker can exploit this vulnerability by sending a crafted URL containing malicious JavaScript, which is then executed in the context of the user's browser, potentially compromising the integrity and confidentiality of the web session.
Users are advised to update the WordPress theme to version 2.18.3 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 15, 2026CISA-ADP
Assessed Sep 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/italia/design-scuole-wordpress-theme | ENISA | ProductSource CodeVendor |
| https://www.acn.gov.it/portale/w/rilevate-vulnerabilita-nel-tema-wordpress-design-scuole-italia- | ENISA | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ENISA |
Affected Products
| Product | Versions |
|---|---|
| Italia Design Scuole Italia | < 2.18.3 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 15, 2026 | CVE Modified | CISA-ADP |
| Sep 15, 2026 | New CVE Received | ENISA |
Volerion