Retour à la veille

CVE-2026-87792

Publié : 15 septembre 2026
Modifié : 18 septembre 2026
Lien officiel NVD

Description détaillée

The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions, allowing an unauthenticated attacker to access restricted "Circolare" content and registered users' data. An unauthenticated RSS feed at /circolare/feed/ further facilitates exploitation.

Références et Patchs