Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions, allowing an unauthenticated attacker to access restricted "Circolare" content and registered users' data. An unauthenticated RSS feed at /circolare/feed/ further facilitates exploitation. | |
| Title | Multiple authorization bypass in WordPress theme design-scuole-wordpress-theme | |
| First Time appeared |
Developers Italia
Developers Italia design-scuole-wordpress-theme |
|
| Weaknesses | CWE-200 CWE-862 |
|
| CPEs | cpe:2.3:a:developers_italia:design-scuole-wordpress-theme:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Developers Italia
Developers Italia design-scuole-wordpress-theme |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ENISA
Published:
Updated: 2026-09-15T17:31:45.662Z
Reserved: 2026-09-09T09:28:48.222Z
Link: CVE-2026-87792
Updated: 2026-09-15T17:26:28.915Z
Status : Received
Published: 2026-09-15T16:17:37.197
Modified: 2026-09-15T18:19:35.877
Link: CVE-2026-87792
No data.
OpenCVE Enrichment
No data.