SEPTEMBER 16, 2026
Live Feed
Back to database
Case File

CVE-2026-87791

HIGH · CVSS 8.7 EPSS 0.40% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

A path traversal vulnerability in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme allows unauthenticated attackers to download arbitrary files from the server. This could lead to the exposure of sensitive information and compromise the integrity of the affected WordPress installations. Website administrators using this theme should prioritize patching this vulnerability to mitigate potential data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-87791
Severity
HIGH
CVSS
8.7
EPSS
0.40%
WordPress

Original NVD Description

A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme. The vulnerability allows an unauthenticated attacker to download arbitrary files accessible by the web server process.