HTML injection allows open redirection in WordPress theme design-scuole-wordpress-theme
Summary
| CVE | CVE-2026-89307 |
|---|---|
| State | PUBLISHED |
| Assigner | ENISA |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-15 16:17:39 UTC |
| Updated | 2026-09-18 19:24:36 UTC |
| Description | The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (Stored HTML Injection / Open Redirect). |
Risk And Classification
Primary CVSS: v4.0 5.1 MEDIUM from a6d3dc9e-0591-4a13-bce7-0f5b31ff6158
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.002830000 probability, percentile 0.210560000 (date 2026-09-18)
Problem Types: CWE-601 | CWE-601 CWE-601 URL redirection to untrusted site ('open redirect')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | a6d3dc9e-0591-4a13-bce7-0f5b31ff6158 | Secondary | 5.1 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 5.1 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
NonePrivileges Required
LowUser Interaction
PassiveConfidentiality
NoneIntegrity
LowAvailability
NoneSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Developers Italia | Design-scuole-wordpress-theme | affected 1.0 2.17.3 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/italia/design-scuole-wordpress-theme | a6d3dc9e-0591-4a13-bce7-0f5b31ff6158 | github.com | |
| www.acn.gov.it/portale/w/rilevate-vulnerabilita-nel-tema-wordpress-design-sc... | a6d3dc9e-0591-4a13-bce7-0f5b31ff6158 | www.acn.gov.it | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Lorenzo Zarfati (en)
CNA: CSIRT-IT (en)
There are currently no legacy QID mappings associated with this CVE.