“Design Scuole Italia” WordPress 主题在 和 函数中存在多个授权绕过漏洞,允许未认证的攻击者访问受限制的“Circolare”(通告/公告)内容以及注册用户的数据。此外,位于 的未认证 RSS 订阅源进一步促进了漏洞利用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Developers Italia | design-scuole-wordpress-theme | 1.0 ~ 2.17.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87791 | 8.7 HIGH | Path traversal vulnerability in WordPress theme design-scuole-wordpress-theme |
| CVE-2026-89307 | 5.1 MEDIUM | HTML injection allows open redirection in WordPress theme design-scuole-wordpress-theme |
| CVE-2026-87793 | 5.1 MEDIUM | Reflected XSS in WordPress theme design-scuole-wordpress-theme |
No comments yet