{"id":"CVE-2026-87792","title":"The \"Design Scuole Italia\" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions, allowing an unauthenticated attacker to access restricted \"Circolare\" conte…","summary":"The \"Design Scuole Italia\" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions, allowing an unauthenticated attacker to access restricted \"Circolare\" conte…","severity":"high","cvss":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-200","CWE-862"],"vendor":"Developers Italia","product":"design-scuole-wordpress-theme","affected":["design-scuole-wordpress-theme >= 1.0 <= 2.17.3"],"published":"2026-09-15","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:24:36.593","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-87792","references":[{"url":"https://github.com/italia/design-scuole-wordpress-theme","label":"a6d3dc9e-0591-4a13-bce7-0f5b31ff6158"},{"url":"https://www.acn.gov.it/portale/w/rilevate-vulnerabilita-nel-tema-wordpress-design-scuole-italia-","label":"a6d3dc9e-0591-4a13-bce7-0f5b31ff6158"}],"tags":["nvd","cve.org"],"epss":0.00359,"epssPercentile":0.29567,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-15T17:17:00.469779Z"},"cvssSource":"cna","ingestedAt":"2026-09-15T15:39:12.906Z","slug":"CVE-2026-87792","body":"## Overview\n\nThe \"Design Scuole Italia\" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions, allowing an unauthenticated attacker to access restricted \"Circolare\" content and registered users' data. An unauthenticated RSS feed at /circolare/feed/ further facilitates exploitation.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":47.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}