PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-87792 Developers Italia CVE debrief

The CVE-2026-87792 vulnerability affects the 'Design Scuole Italia' WordPress theme, allowing unauthenticated attackers to access restricted content and user data due to multiple authorization bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions. This vulnerability has a CVSS score of 8.7, indicating high severity. The vulnerability's impact includes potential data exposure and exploitation through an unauthenticated RSS feed at /circolare/feed/. Defenders should prioritize verification and mitigation, especially for WordPress installations using this theme.

Vendor
Developers Italia
Product
design-scuole-wordpress-theme
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-15
Original CVE updated
2026-09-18
Advisory published
2026-09-15
Advisory updated
2026-09-18

Who should care

Defenders responsible for WordPress installations using the 'Design Scuole Italia' theme should assess exposure and prioritize mitigation. Security teams and administrators should verify the presence of this theme in their environment and monitor for potential exploitation attempts.

Why it matters

CVE-2026-87792 is a high-severity vulnerability in the 'Design Scuole Italia' WordPress theme that allows unauthorized access to restricted content and user data. Defenders should prioritize verification and mitigation, especially for WordPress installations using this theme. The vulnerability's impact includes potential data exposure and exploitation through an unauthenticated RSS feed. Remediation priority is high, but specific steps require verification from official sources.

  • Potential unauthorized access to sensitive content and user data.
  • Possible exploitation through the unauthenticated RSS feed.
  • Need for verification of affected versions and remediation steps.
  • Priority for updating or patching the vulnerable theme.

Technical summary

The 'Design Scuole Italia' WordPress theme is affected by multiple authorization bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions. These vulnerabilities allow an unauthenticated attacker to access restricted 'Circolare' content and registered users' data. An unauthenticated RSS feed at /circolare/feed/ further facilitates exploitation. The vulnerability has a CVSS score of 8.7, indicating high severity. Defenders should prioritize verifying and mitigating this vulnerability, especially for WordPress installations using the 'Design Scuole Italia' theme.

Defensive priority

Defenders should prioritize verifying and mitigating this vulnerability, especially for WordPress installations using the 'Design Scuole Italia' theme.

Recommended defensive actions

  • Verify if the 'Design Scuole Italia' WordPress theme is in use and prioritize updates or patches if available.
  • Restrict access to the /circolare/feed/ RSS feed to prevent exploitation.
  • Monitor for potential unauthorized access to restricted 'Circolare' content and user data.
  • Consider implementing additional security measures for WordPress installations, such as authentication and authorization checks.
  • Review and update incident response plans to address potential exploitation of this vulnerability.
  • Conduct a thorough review of the affected system's configuration and user data to identify potential security risks.
  • Implement network segmentation to limit the spread of potential attacks.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its CVSS score of 8.7 and the affected theme. However, specific details about affected versions and remediation are not provided in the corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-87792 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-87792

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-87792 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87792

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/italia/design-scuole-wordpress-theme

    a6d3dc9e-0591-4a13-bce7-0f5b31ff6158

  • Source reference

    Unverified legacy reference

    URL: https://www.acn.gov.it/portale/w/rilevate-vulnerabilita-nel-tema-wordpress-design-scuole-italia-

    a6d3dc9e-0591-4a13-bce7-0f5b31ff6158

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.