---
id: CVE-2026-89307
title: >-
  The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme
  allows an authenticated attacker to inject arbitrary HTML via the sign
  parameter, enabling forced redirection of visiting users to an
  attacker-controlled URL (St…
summary: >-
  The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme
  allows an authenticated attacker to inject arbitrary HTML via the sign
  parameter, enabling forced redirection of visiting users to an
  attacker-controlled URL (St…
severity: medium
cvss: 5.1
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-601
vendor: Developers Italia
product: design-scuole-wordpress-theme
affected:
  - design-scuole-wordpress-theme >= 1.0 <= 2.17.3
published: '2026-09-15'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:24:36.593'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89307'
references:
  - url: 'https://github.com/italia/design-scuole-wordpress-theme'
    label: a6d3dc9e-0591-4a13-bce7-0f5b31ff6158
  - url: >-
      https://www.acn.gov.it/portale/w/rilevate-vulnerabilita-nel-tema-wordpress-design-scuole-italia-
    label: a6d3dc9e-0591-4a13-bce7-0f5b31ff6158
tags:
  - nvd
  - cve.org
epss: 0.00283
epssPercentile: 0.21064
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T17:16:36.848070Z'
cvssSource: cna
ingestedAt: '2026-09-15T15:39:12.905Z'
---

## Overview

The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (Stored HTML Injection / Open Redirect).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
