Bello - Directory & Listing [bello] < 1.6.0
unknown
[en] The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise its post_excerpt parameter before outputting it back in the shop/my-account/bello-listing-endpoint/ page, leading to a Cross-Site Scripting issue
- Affected:
- up to 1.6.0
- Fixed in:
- 1.6.0
- Disclosed:
- Jun 1, 2021
CVE-2021-24319 on NVD →
Bello - Directory & Listing [bello] < 1.6.0
unknown
[en] The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise and escape its listing_list_view, bt_bb_listing_field_my_lat, bt_bb_listing_field_my_lng, bt_bb_listing_field_distance_value, bt_bb_listing_field_my_lat_default, bt_bb_listing_field_keyword, bt_bb_listing_field_location_autocomp...
- Affected:
- up to 1.6.0
- Fixed in:
- 1.6.0
- Disclosed:
- Jun 1, 2021
CVE-2021-24320 on NVD →
Bello - Directory & Listing [bello] < 1.6.0
unknown
[en] The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt_bb_listing_field_now_open, bt_bb_listing_field_my_lng, listing_list_view and bt_bb_listing_field_my_lat parameters before using them in a SQL statement, leading to SQL Injection issues
- Affected:
- up to 1.6.0
- Fixed in:
- 1.6.0
- Disclosed:
- Jun 1, 2021
CVE-2021-24321 on NVD →
Bello - Directory & Listing <= 1.5.9 - Unauthenticated SQL Injection
critical
The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt_bb_listing_field_now_open, bt_bb_listing_field_my_lng, listing_list_view and bt_bb_listing_field_my_lat parameters before using them in a SQL statement, leading to SQL Injection issues.
- CVSS:
- 9.8
- Affected:
- up to 1.6.0
- Fixed in:
- 1.6.0
- Disclosed:
- May 16, 2021
CVE-2021-24321 on NVD →
Bello - Directory & Listing - < 1.6.0 - Cross-Site Scripting
medium
The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise its post_excerpt parameter before outputting it back in the shop/my-account/bello-listing-endpoint/ page, leading to a Cross-Site Scripting issue
- CVSS:
- 6.4
- Affected:
- up to 1.6.0
- Fixed in:
- 1.6.0
- Disclosed:
- May 16, 2021
CVE-2021-24319 on NVD →
Bello - Directory & Listing [bello] < 1.5.8
unknown
Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by m0ze WordPress Bello - Directory & Listing premium theme (versions <= 1.5.7).
- Affected:
- up to 1.5.8
- Fixed in:
- 1.5.8
- Disclosed:
- Mar 31, 2021
Bello - Directory & Listing [bello] < 1.5.8
unknown
Unauthenticated SQL Injection (SQLi) vulnerability discovered by m0ze in WordPress Bello - Directory & Listing premium theme (versions <= 1.5.7).
- Affected:
- up to 1.5.8
- Fixed in:
- 1.5.8
- Disclosed:
- Mar 31, 2021
Directory & Listing < 1.6.0 - Reflected Cross-Site Scripting
medium
The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise and escape its listing_list_view, bt_bb_listing_field_my_lat, bt_bb_listing_field_my_lng, bt_bb_listing_field_distance_value, bt_bb_listing_field_my_lat_default, bt_bb_listing_field_keyword, bt_bb_listing_field_location_autocomplete,...
- CVSS:
- 6.1
- Affected:
- up to 1.6.0
- Fixed in:
- 1.6.0
- Disclosed:
- Mar 21, 2021
CVE-2021-24320 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database