Junglewise Threat Intelligence

CVE-2026-87792: Design Scuole Italia WordPress theme authorization bypass in PDF/CSV generators

CVE-2026-87792 · Severity: info · CVSS 8.7 · Published 2026-09-15

Executive brief

The Design Scuole Italia WordPress theme, used by Italian schools to build official institutional websites, contains authorization bypass vulnerabilities in its PDF and CSV export functions. An unauthenticated attacker can bypass access controls to download restricted school notices ("Circolari") and access personal data of registered users, potentially exposing sensitive educational and administrative information.

Technical details

The vulnerability is an authorization bypass in the dsi_pdf_generator and dsi_csv_generator functions that fail to properly validate user permissions before exporting data. An unauthenticated attacker can send crafted requests to bypass access controls and retrieve restricted "Circolare" content and registered user information. The attack requires network access to the WordPress site; no user interaction or authentication is needed. The publicly accessible RSS feed at /circolare/feed/ can be exploited to enumerate and discover exposed content. The vulnerability affects all versions prior to 2.18.3, and patches are available in the latest release.

Affected products

  • Italia Design Scuole Italia WordPress theme prior to 2.18.3

Timeline

  • 2026-09-15: disclosed: CVE-2026-87792 published by NVD and Italian CSIRT

References

Related threats