Impact
The vulnerability resides in the dsi_pdf_generator and dsi_csv_generator functions of the Design Scuole Italia WordPress theme, allowing an attacker who is not logged in to retrieve restricted Circolare documents and personal information of registered users. This bypass of authorization controls directly compromises confidentiality and may expose sensitive business or personal data. The flaw is categorized under CWE-200 (Information Exposure) and CWE-862 (Authorization Bypass Through User-Controlled Key).
Affected Systems
All installations of the Design Scuole Italia theme published by Developers Italia are impacted. No specific version range is listed in the advisory, so any instance of the theme where the dsi_pdf_generator or dsi_csv_generator functions are active is vulnerable.
Risk and Exploitability
The CVSS score of 8.7 indicates a high impact, with the threat scenario requiring no authentication and leveraging standard HTTPS endpoints. The EPSS score of < 1% indicates a low probability of exploitation, but the presence of an unauthenticated RSS feed at /circolare/feed/ suggests an easy reconnaissance vector. The vulnerability is not currently listed in the CISA KEV catalog, but the lack of authentication combined with the ability to extract data makes it a candidate for widespread exploitation if left unpatched.
OpenCVE Enrichment