m0ze.ru
https://m0ze.ru/vulnerability/%5B2021-03-21%5D-%5BWordPress%5D-%5BCWE-1021%5D-Bello-WordPress-Theme-v1.5.9.txt CVE-2021-24319
MEDIUM
Bello < 1.6.0 - Authenticated Cross-Site Scripting (XSS) and XFS
Record summary
CVE-2021-24319 has a selected CVSS score of 5.4 (medium).
Description
The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise its post_excerpt parameter before outputting it back in the shop/my-account/bello-listing-endpoint/ page, leading to a Cross-Site Scripting issue
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Bello - Directory & ListingBrowse BoldThemes / Bello - Directory & Listing | CVE List | 1.6.0 to < 1.6.0 | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-24319 wpscan.comConfirmation
https://wpscan.com/vulnerability/2c274eb7-25f1-49d4-a2c8-8ce8cecebe68