CVE-2026-89307 Details
Description
The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (Stored HTML Injection / Open Redirect).
A vulnerability allowing stored HTML injection and open redirection has been identified in the Design Scuole Italia WordPress theme, specifically in versions prior to 2.18.3. This issue arises within the 'Firma Circolare' feature, where an authenticated attacker can inject arbitrary HTML through the 'sign' parameter. The injected HTML can include a link, which, when clicked by users, redirects them to an attacker-controlled URL.
Users are advised to update the WordPress theme to the latest version available.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 15, 2026CISA-ADP
Assessed Sep 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/italia/design-scuole-wordpress-theme | ENISA | Source CodeVendor |
| https://www.acn.gov.it/portale/w/rilevate-vulnerabilita-nel-tema-wordpress-design-scuole-italia- | ENISA | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') | ENISA |
Affected Products
| Product | Versions |
|---|---|
| Italia Design Scuole Italia | < 2.18.3 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 15, 2026 | CVE Modified | CISA-ADP |
| Sep 15, 2026 | New CVE Received | ENISA |
Volerion