VulnSea

design-scuole-wordpress-theme vulnerabilities

CVEs whose affected-version data names the design-scuole-wordpress-theme package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-87791High· 8.7
1w ago

A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme

A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme. The vulnerability allows an unauthenticated attacker to download arbitrary files accessible …

TwilightDevelopers Italia · design-scuole-wordpress-themeEPSS 0.40%via NVD
CVE-2026-87793Medium· 5.1
1w ago

The "Design Scuole Italia" WordPress theme is affected by a Reflected XSS vulnerability in the filters-scheda-didattica.php file, allowing an unauthenticated attacker to execute arbitrary JavaScript in a victim's browser via a crafted …

The "Design Scuole Italia" WordPress theme is affected by a Reflected XSS vulnerability in the filters-scheda-didattica.php file, allowing an unauthenticated attacker to execute arbitrary JavaScript in a victim's browser via a crafted …

SunlitDevelopers Italia · design-scuole-wordpress-themeEPSS 0.40%via NVD
CVE-2026-87792High· 8.7
1w ago

The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions, allowing an unauthenticated attacker to access restricted "Circolare" conte…

The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions, allowing an unauthenticated attacker to access restricted "Circolare" conte…

TwilightDevelopers Italia · design-scuole-wordpress-themeEPSS 0.36%via NVD
CVE-2026-89307Medium· 5.1
1w ago

The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (St…

The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (St…

SunlitDevelopers Italia · design-scuole-wordpress-themeEPSS 0.28%via NVD
design-scuole-wordpress-theme vulnerabilities (CVEs) · VulnSea