PatchSiren cyber security CVE debrief
CVE-2026-87792 Developers Italia CVE debrief
The CVE-2026-87792 vulnerability affects the 'Design Scuole Italia' WordPress theme, allowing unauthenticated attackers to access restricted content and user data due to multiple authorization bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions. This vulnerability has a CVSS score of 8.7, indicating high severity. The vulnerability's impact includes potential data exposure and exploitation through an unauthenticated RSS feed at /circolare/feed/. Defenders should prioritize verification and mitigation, especially for WordPress installations using this theme.
- Vendor
- Developers Italia
- Product
- design-scuole-wordpress-theme
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-18
Who should care
Defenders responsible for WordPress installations using the 'Design Scuole Italia' theme should assess exposure and prioritize mitigation. Security teams and administrators should verify the presence of this theme in their environment and monitor for potential exploitation attempts.
Why it matters
CVE-2026-87792 is a high-severity vulnerability in the 'Design Scuole Italia' WordPress theme that allows unauthorized access to restricted content and user data. Defenders should prioritize verification and mitigation, especially for WordPress installations using this theme. The vulnerability's impact includes potential data exposure and exploitation through an unauthenticated RSS feed. Remediation priority is high, but specific steps require verification from official sources.
- Potential unauthorized access to sensitive content and user data.
- Possible exploitation through the unauthenticated RSS feed.
- Need for verification of affected versions and remediation steps.
- Priority for updating or patching the vulnerable theme.
Technical summary
The 'Design Scuole Italia' WordPress theme is affected by multiple authorization bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions. These vulnerabilities allow an unauthenticated attacker to access restricted 'Circolare' content and registered users' data. An unauthenticated RSS feed at /circolare/feed/ further facilitates exploitation. The vulnerability has a CVSS score of 8.7, indicating high severity. Defenders should prioritize verifying and mitigating this vulnerability, especially for WordPress installations using the 'Design Scuole Italia' theme.
Defensive priority
Defenders should prioritize verifying and mitigating this vulnerability, especially for WordPress installations using the 'Design Scuole Italia' theme.
Recommended defensive actions
- Verify if the 'Design Scuole Italia' WordPress theme is in use and prioritize updates or patches if available.
- Restrict access to the /circolare/feed/ RSS feed to prevent exploitation.
- Monitor for potential unauthorized access to restricted 'Circolare' content and user data.
- Consider implementing additional security measures for WordPress installations, such as authentication and authorization checks.
- Review and update incident response plans to address potential exploitation of this vulnerability.
- Conduct a thorough review of the affected system's configuration and user data to identify potential security risks.
- Implement network segmentation to limit the spread of potential attacks.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its CVSS score of 8.7 and the affected theme. However, specific details about affected versions and remediation are not provided in the corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-87792 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-87792
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-87792 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87792
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/italia/design-scuole-wordpress-theme
a6d3dc9e-0591-4a13-bce7-0f5b31ff6158
-
Source reference
Unverified legacy reference
URL: https://www.acn.gov.it/portale/w/rilevate-vulnerabilita-nel-tema-wordpress-design-scuole-italia-
a6d3dc9e-0591-4a13-bce7-0f5b31ff6158
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.