Description
A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme. The vulnerability allows an unauthenticated attacker to download arbitrary files accessible by the web server process.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update to version 2.18.2
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme. The vulnerability allows an unauthenticated attacker to download arbitrary files accessible by the web server process. | |
| Title | Path traversal vulnerability in WordPress theme design-scuole-wordpress-theme | |
| First Time appeared |
Developers Italia
Developers Italia design-scuole-wordpress-theme |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:developers_italia:design-scuole-wordpress-theme:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Developers Italia
Developers Italia design-scuole-wordpress-theme |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ENISA
Published:
Updated: 2026-09-15T17:31:45.818Z
Reserved: 2026-09-09T09:28:48.222Z
Link: CVE-2026-87791
No data.
Status : Received
Published: 2026-09-15T16:17:37.060
Modified: 2026-09-15T16:17:37.060
Link: CVE-2026-87791
No data.
OpenCVE Enrichment
No data.
Weaknesses