PT-2021-15856 · WordPress · The Bello

M0Ze

+1

·

Published

2021-06-01

·

Updated

2021-08-12

·

CVE-2021-24319

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Bello - Directory & Listing WordPress theme versions prior to 1.6.0
Description The issue arises from the theme not properly sanitizing its post excerpt parameter before outputting it back in the "shop/my-account/bello-listing-endpoint/" page, leading to a Cross-Site Scripting issue.
Recommendations For versions prior to 1.6.0, update to version 1.6.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the "shop/my-account/bello-listing-endpoint/" page until the update is applied. Avoid using the post excerpt parameter in the affected page until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24319

Affected Products

The Bello