A AegiFlow
MEDIUMCVSS 5.1

CVE-2026-89307

CVE-2026-89307 updated by NVD

Published
2026-09-15
Modified
2026-09-20
Sources
euvd, nvd

Summary

The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (Stored HTML Injection / Open Redirect).

References

Includes data from the ENISA EU Vulnerability Database (EUVD).

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.