CVE-2026-87791
A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme. The vulnerability allows an unauthenticated attacker to download arbitrary files accessible by the web server process.
- Published Sep 15, 2026
- CVSS 8.7 high
- 0.5% chance of exploitation in the next 30 days (EPSS)