Description
The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions, allowing an unauthenticated attacker to access restricted "Circolare" content and registered users' data. An unauthenticated RSS feed at /circolare/feed/ further facilitates exploitation.
Published: 2026-09-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to protected content and user data
Action: Patch Immediately
AI Analysis

Impact

The vulnerability resides in the dsi_pdf_generator and dsi_csv_generator functions of the Design Scuole Italia WordPress theme, allowing an attacker who is not logged in to retrieve restricted Circolare documents and personal information of registered users. This bypass of authorization controls directly compromises confidentiality and may expose sensitive business or personal data. The flaw is categorized under CWE-200 (Information Exposure) and CWE-862 (Authorization Bypass Through User-Controlled Key).

Affected Systems

All installations of the Design Scuole Italia theme published by Developers Italia are impacted. No specific version range is listed in the advisory, so any instance of the theme where the dsi_pdf_generator or dsi_csv_generator functions are active is vulnerable.

Risk and Exploitability

The CVSS score of 8.7 indicates a high impact, with the threat scenario requiring no authentication and leveraging standard HTTPS endpoints. The EPSS score of < 1% indicates a low probability of exploitation, but the presence of an unauthenticated RSS feed at /circolare/feed/ suggests an easy reconnaissance vector. The vulnerability is not currently listed in the CISA KEV catalog, but the lack of authentication combined with the ability to extract data makes it a candidate for widespread exploitation if left unpatched.

Generated by OpenCVE AI on September 20, 2026 at 16:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Design Scuole Italia theme to the latest revision that includes fixes for the PDF and CSV generator functions
  • Disable or secure the /circolare/feed/ RSS endpoint so that it requires authentication or is removed
  • If the theme must remain on the vulnerable version, block unauthenticated requests to the dsi_pdf_generator and dsi_csv_generator URLs via server or application firewall rules

Generated by OpenCVE AI on September 20, 2026 at 16:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions, allowing an unauthenticated attacker to access restricted "Circolare" content and registered users' data. An unauthenticated RSS feed at /circolare/feed/ further facilitates exploitation.
Title Multiple authorization bypass in WordPress theme design-scuole-wordpress-theme
First Time appeared Developers Italia
Developers Italia design-scuole-wordpress-theme
Weaknesses CWE-200
CWE-862
CPEs cpe:2.3:a:developers_italia:design-scuole-wordpress-theme:*:*:*:*:*:*:*:*
Vendors & Products Developers Italia
Developers Italia design-scuole-wordpress-theme
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Developers Italia Design-scuole-wordpress-theme
cve-icon MITRE

Status: PUBLISHED

Assigner: ENISA

Published:

Updated: 2026-09-15T17:31:45.662Z

Reserved: 2026-09-09T09:28:48.222Z

Link: CVE-2026-87792

cve-icon Vulnrichment

Updated: 2026-09-15T17:26:28.915Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:37.197

Modified: 2026-09-18T19:24:36.593

Link: CVE-2026-87792

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:15:18Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-862

    Missing Authorization