CVE-2026-87791: Path traversal vulnerability in WordPress theme design-scuole-wordpress-theme
A path traversal vulnerability exists in the reservedfilecheck function of the functions.php file in the WordPress Design Scuole Italia theme. The vulnerability allows an unauthenticated attacker to download arbitrary files accessible by the web server process.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Design Scuole Italia theme (design-scuole-wordpress-theme)to a version that resolves this vulnerability.Fixed in 2.18.2
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker can exploit it; no login or WordPress account is required.
What could an attacker access?
The issue can allow downloading arbitrary files that are accessible to the web server process. Files outside the intended theme path may be exposed if the web server account can read them.
How can I determine whether my site is affected?
Check whether the site uses the WordPress Design Scuole Italia theme and inspect its functions.php file for the reserved_file_check function. The provided information does not identify affected or fixed theme versions.