PT-2021-15858 · WordPress · The Bello

M0Ze

+1

·

Published

2021-06-01

·

Updated

2021-08-12

·

CVE-2021-24321

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Bello - Directory & Listing WordPress theme versions prior to 1.6.0
Description The issue arises from the lack of sanitization of certain parameters before they are used in SQL statements, leading to SQL Injection issues. The parameters bt bb listing field price range to, bt bb listing field now open, bt bb listing field my lng, listing list view, and bt bb listing field my lat are not properly sanitized.
Recommendations For versions prior to 1.6.0, update to version 1.6.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the parameters bt bb listing field price range to, bt bb listing field now open, bt bb listing field my lng, listing list view, and bt bb listing field my lat to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24321

Affected Products

The Bello