Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-89307

Опубликовано: 15 сент. 2026
Источник: nvd
EPSS Низкий

Описание

The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (Stored HTML Injection / Open Redirect).

EPSS

Процентиль: 21%
0.00283
Низкий

Дефекты

CWE-601

Связанные уязвимости

github
8 дней назад

The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (Stored HTML Injection / Open Redirect).

EPSS

Процентиль: 21%
0.00283
Низкий

Дефекты

CWE-601