Impact
The Vulnerability permits an authenticated user to inject arbitrary HTML into the 'sign' parameter of the 'Firma Circolare' feature in the Design Scuole Italia WordPress theme. The injected content causes the web page to perform a forced redirection to an attacker‑controlled URL, enabling phishing or malicious site delivery. This weakness is a typical Stored HTML Injection/Open Redirect, identified by CWE-601.
Affected Systems
The affected product is the WordPress theme Design Scuole Italia developed by Developers Italia. Version information is not supplied in the CNA data; administrators should verify the theme version in use and compare it to the latest official release.
Risk and Exploitability
The CVSS score of 5.1 indicates medium risk. The EPSS score is less than 1%, indicating a low but non‑zero probability that the vulnerability could be exploited, and the vulnerability is not listed in the CISA KEV catalog. Attackers must first be authenticated to the WordPress site to manipulate the sign parameter. Once the attack vector is triggered, any visitor to the manipulated page will be redirected, potentially compromising user trust and exposing them to malware or phishing targets.
OpenCVE Enrichment