CVE-2026-87792: Developers Italia Design-Scuole-WordPress-Theme

High severity, CVSS 8.7. EPSS: 0.5% chance of exploitation in the next 30 days.

The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions, allowing an unauthenticated attacker to access restricted "Circolare" content and registered users' data. An unauthenticated RSS feed at /circolare/feed/ further facilitates exploitation.

Affected products

  • Developers Italia Design-Scuole-WordPress-Theme: from 1.0, up to and including 2.17.3

Published 2026-09-15. Last modified 2026-09-18.