PT-2026-92044 · WordPress · Design Scuole Italia Theme

·

CVE-2026-87791

·

Published

2026-09-15

·

Updated

2026-09-24

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions WordPress Design Scuole Italia theme (affected versions not specified)
Description A path traversal issue exists in the reserved file check() function within the functions.php file. This flaw allows an unauthenticated attacker to download arbitrary files that are accessible by the web server process. Path traversal is a technique used to access files and directories that are stored outside the web root folder.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the reserved file check() function until a patch is available.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-87791

Affected Products

Design Scuole Italia Theme