CVE-2021-24320
MEDIUM NUCLEIBold-themes Bello < 1.6.0 - XSS
Title source: ruleDescription
The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise and escape its listing_list_view, bt_bb_listing_field_my_lat, bt_bb_listing_field_my_lng, bt_bb_listing_field_distance_value, bt_bb_listing_field_my_lat_default, bt_bb_listing_field_keyword, bt_bb_listing_field_location_autocomplete, bt_bb_listing_field_price_range_from and bt_bb_listing_field_price_range_to parameter in ints listing page, leading to reflected Cross-Site Scripting issues.
Nuclei Templates (1)
WordPress Bello Directory & Listing Theme <1.6.0 - Cross-Site Scripting
MEDIUMby daffainfo
Scores
CVSS v3
6.1
EPSS
0.5035
EPSS Percentile
97.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
bold-themes/bello
< 1.6.0
Published
Jun 01, 2021
Tracked Since
Feb 18, 2026