WordPress · Design Scuole Italia Theme · CVE-2026-87791
**Name of the Vulnerable Software and Affected Versions**
WordPress Design Scuole Italia theme (affected versions not specified)
**Description**
A path traversal issue exists in the `reserved file check()` function within the `functions.php` file. This flaw allows an unauthenticated attacker to download arbitrary files that are accessible by the web server process. Path traversal is a technique used to access files and directories that are stored outside the web root folder.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider restricting access to the `reserved file check()` function until a patch is available.