Impact
A path traversal flaw in the reserved_file_check function of the WordPress Design Scuole Italia theme allows an unauthenticated attacker to request and download any file that the web server can read. By manipulating URLs that invoke the vulnerable function, an attacker can obtain configuration files, database credentials, or user‑uploaded data, leading to confidential information disclosure.
Affected Systems
The flaw affects installations of the Developers Italia Design Scuole WordPress theme. Any site running this theme should upgrade to version 2.18.2 or later to eliminate the vulnerability. No specific older version numbers are listed as affected, but the presence of the reserved_file_check function implies that all releases prior to 2.18.2 are at risk.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity weakness. The EPSS score of <1% indicates a very low exploitation probability, but the vulnerability can still be exploited by simply forming a crafted URL; no user authentication is required. The flaw is not listed in CISA's KEV catalog at this time, but the evidence of unauthenticated file download strongly suggests that attackers can actively exploit it. The high potential for data exposure coupled with easy access makes this a critical risk for sites using the theme.
OpenCVE Enrichment