The CVE-2026-89307 vulnerability in the Design Scuole Italia WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL. This stored HTML injection and open redirect vulnerability has a CVSS score of 5.1, indicating a medium severity level.
The CVE-2026-87793 vulnerability is a Reflected XSS issue in the 'Design Scuole Italia' WordPress theme. An unauthenticated attacker can exploit this by crafting a URL with a malicious 'archive' parameter, allowing them to execute arbitrary JavaScript in a victim's browser. The CVSS score for this vulnerability is 5.1, indicating a medium severity level.
The CVE-2026-87792 vulnerability affects the 'Design Scuole Italia' WordPress theme, allowing unauthenticated attackers to access restricted content and user data due to multiple authorization bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions. This vulnerability has a CVSS score of 8.7, indicating high severity. The vulnerability's impact includes potential data exposure and [truncated]
CVE-2026-87791 is a high-severity path traversal vulnerability in the WordPress Design Scuole Italia theme's functions.php file. This vulnerability allows unauthenticated attackers to download arbitrary files accessible by the web server process. Defenders should assess exposure and implement compensating controls due to the high CVSS score of 8.7. The vulnerability exists in the reserved_file_check funct [truncated]