MajorCritical vulnerability
CVE-2026-87791 (CVSS 8.7)
NVD · officialPublished Sep 15, 2026Risk 37/100EPSS 0.4%
A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme. The vulnerability allows an unauthenticated attacker to download arbitrary files accessible by the web server process.
Technical details
CVSS
8.7
AV:NetworkAC:LowPR:NoneUI:None
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source