Description
The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (Stored HTML Injection / Open Redirect).
Published: 2026-09-15
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored HTML injection leading to open redirection
Action: Apply patch
AI Analysis

Impact

The Vulnerability permits an authenticated user to inject arbitrary HTML into the 'sign' parameter of the 'Firma Circolare' feature in the Design Scuole Italia WordPress theme. The injected content causes the web page to perform a forced redirection to an attacker‑controlled URL, enabling phishing or malicious site delivery. This weakness is a typical Stored HTML Injection/Open Redirect, identified by CWE-601.

Affected Systems

The affected product is the WordPress theme Design Scuole Italia developed by Developers Italia. Version information is not supplied in the CNA data; administrators should verify the theme version in use and compare it to the latest official release.

Risk and Exploitability

The CVSS score of 5.1 indicates medium risk. The EPSS score is less than 1%, indicating a low but non‑zero probability that the vulnerability could be exploited, and the vulnerability is not listed in the CISA KEV catalog. Attackers must first be authenticated to the WordPress site to manipulate the sign parameter. Once the attack vector is triggered, any visitor to the manipulated page will be redirected, potentially compromising user trust and exposing them to malware or phishing targets.

Generated by OpenCVE AI on September 20, 2026 at 16:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Design Scuole Italia WordPress theme to the latest patched version that removes the vulnerable sign parameter handling.
  • If an update is unavailable, temporarily disable or remove the 'Firma Circolare' feature until a fix is released to prevent exploitation.
  • Validate the sign parameter strictly—whitelist allowed characters or values and reject any unexpected input before outputting HTML to the page.

Generated by OpenCVE AI on September 20, 2026 at 16:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Tue, 15 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (Stored HTML Injection / Open Redirect).
Title HTML injection allows open redirection in WordPress theme design-scuole-wordpress-theme
First Time appeared Developers Italia
Developers Italia design-scuole-wordpress-theme
Weaknesses CWE-601
CPEs cpe:2.3:a:developers_italia:design-scuole-wordpress-theme:*:*:*:*:*:*:*:*
Vendors & Products Developers Italia
Developers Italia design-scuole-wordpress-theme
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Developers Italia Design-scuole-wordpress-theme
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: ENISA

Published:

Updated: 2026-09-15T17:31:45.292Z

Reserved: 2026-09-11T13:54:43.619Z

Link: CVE-2026-89307

cve-icon Vulnrichment

Updated: 2026-09-15T17:26:24.663Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:39.863

Modified: 2026-09-18T19:24:36.593

Link: CVE-2026-89307

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:15:18Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')