CVE-2026-89307: HTML injection allows open redirection in WordPress theme design-scuole-wordpress-theme
The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (Stored HTML Injection / Open Redirect).
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated and able to use the theme's "Firma Circolare" feature with control over the sign parameter.
What is the impact on site visitors?
Injected HTML can cause visitors to be forcibly redirected to an attacker-controlled URL. This can support phishing or other malicious destinations reached through an apparently legitimate site.
How can administrators determine whether their site may be affected?
Check whether the site uses the Design Scuole Italia WordPress theme and exposes the "Firma Circolare" functionality to authenticated users. Review uses of the sign parameter for unexpected HTML or redirect-related content.