Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (Stored HTML Injection / Open Redirect). | |
| Title | HTML injection allows open redirection in WordPress theme design-scuole-wordpress-theme | |
| First Time appeared |
Developers Italia
Developers Italia design-scuole-wordpress-theme |
|
| Weaknesses | CWE-601 | |
| CPEs | cpe:2.3:a:developers_italia:design-scuole-wordpress-theme:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Developers Italia
Developers Italia design-scuole-wordpress-theme |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ENISA
Published:
Updated: 2026-09-15T15:23:40.292Z
Reserved: 2026-09-11T13:54:43.619Z
Link: CVE-2026-89307
No data.
Status : Received
Published: 2026-09-15T16:17:39.863
Modified: 2026-09-15T16:17:39.863
Link: CVE-2026-89307
No data.
OpenCVE Enrichment
No data.
-
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')