CVE-2026-87792
The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions, allowing an unauthenticated attacker to access restricted "Circolare" content and registered users' data. An unauthenticated RSS feed at /circolare/feed/ further facilitates exploitation.
- Published Sep 15, 2026
- CVSS 8.7 high
- 0.5% chance of exploitation in the next 30 days (EPSS)