The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (Stored HTML Injection / Open Redirect).
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 15 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (Stored HTML Injection / Open Redirect). | |
| Title | HTML injection allows open redirection in WordPress theme design-scuole-wordpress-theme | |
| First Time appeared |
Developers Italia
Developers Italia design-scuole-wordpress-theme |
|
| Weaknesses | CWE-601 | |
| CPEs | cpe:2.3:a:developers_italia:design-scuole-wordpress-theme:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Developers Italia
Developers Italia design-scuole-wordpress-theme |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ENISA
Published:
Updated: 2026-09-15T15:23:40.292Z
Reserved: 2026-09-11T13:54:43.619Z
Link: CVE-2026-89307
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses