theme

Bello Vulnerabilities

8 known security issues reported for the Bello WordPress theme. Most recent disclosed Jun 1, 2021.

1 critical 2 medium

Running Bello on your site? Check whether your installed version is affected.

Scan your site free

Bello - Directory & Listing [bello] < 1.6.0

unknown

[en] The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise its post_excerpt parameter before outputting it back in the shop/my-account/bello-listing-endpoint/ page, leading to a Cross-Site Scripting issue

Affected:
up to 1.6.0
Fixed in:
1.6.0
Disclosed:
Jun 1, 2021

CVE-2021-24319 on NVD →

Bello - Directory & Listing [bello] < 1.6.0

unknown

[en] The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise and escape its listing_list_view, bt_bb_listing_field_my_lat, bt_bb_listing_field_my_lng, bt_bb_listing_field_distance_value, bt_bb_listing_field_my_lat_default, bt_bb_listing_field_keyword, bt_bb_listing_field_location_autocomp...

Affected:
up to 1.6.0
Fixed in:
1.6.0
Disclosed:
Jun 1, 2021

CVE-2021-24320 on NVD →

Bello - Directory & Listing [bello] < 1.6.0

unknown

[en] The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt_bb_listing_field_now_open, bt_bb_listing_field_my_lng, listing_list_view and bt_bb_listing_field_my_lat parameters before using them in a SQL statement, leading to SQL Injection issues

Affected:
up to 1.6.0
Fixed in:
1.6.0
Disclosed:
Jun 1, 2021

CVE-2021-24321 on NVD →

Bello - Directory & Listing <= 1.5.9 - Unauthenticated SQL Injection

critical

The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt_bb_listing_field_now_open, bt_bb_listing_field_my_lng, listing_list_view and bt_bb_listing_field_my_lat parameters before using them in a SQL statement, leading to SQL Injection issues.

CVSS:
9.8
Affected:
up to 1.6.0
Fixed in:
1.6.0
Disclosed:
May 16, 2021

CVE-2021-24321 on NVD →

Bello - Directory & Listing - < 1.6.0 - Cross-Site Scripting

medium

The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise its post_excerpt parameter before outputting it back in the shop/my-account/bello-listing-endpoint/ page, leading to a Cross-Site Scripting issue

CVSS:
6.4
Affected:
up to 1.6.0
Fixed in:
1.6.0
Disclosed:
May 16, 2021

CVE-2021-24319 on NVD →

Bello - Directory & Listing [bello] < 1.5.8

unknown

Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by m0ze WordPress Bello - Directory & Listing premium theme (versions <= 1.5.7).

Affected:
up to 1.5.8
Fixed in:
1.5.8
Disclosed:
Mar 31, 2021

Bello - Directory & Listing [bello] < 1.5.8

unknown

Unauthenticated SQL Injection (SQLi) vulnerability discovered by m0ze in WordPress Bello - Directory & Listing premium theme (versions <= 1.5.7).

Affected:
up to 1.5.8
Fixed in:
1.5.8
Disclosed:
Mar 31, 2021

Directory & Listing < 1.6.0 - Reflected Cross-Site Scripting

medium

The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise and escape its listing_list_view, bt_bb_listing_field_my_lat, bt_bb_listing_field_my_lng, bt_bb_listing_field_distance_value, bt_bb_listing_field_my_lat_default, bt_bb_listing_field_keyword, bt_bb_listing_field_location_autocomplete,...

CVSS:
6.1
Affected:
up to 1.6.0
Fixed in:
1.6.0
Disclosed:
Mar 21, 2021

CVE-2021-24320 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database