CVE-2026-89307 PUBLISHED

HTML injection allows open redirection in WordPress theme design-scuole-wordpress-theme

Assigner: ENISA
Reserved: 11.09.2026 Published: 15.09.2026 Updated: 15.09.2026

The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (Stored HTML Injection / Open Redirect).

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.1

Product Status

Vendor Developers Italia
Product design-scuole-wordpress-theme
Versions Default: unaffected
  • affected from 1.0 to 2.17.3 (incl.)

Credits

  • Lorenzo Zarfati finder
  • CSIRT-IT coordinator

References

Problem Types

  • CWE-601 URL redirection to untrusted site ('open redirect') CWE

Impacts

  • CAPEC-98 Phishing