CVE-2021-24319: Bello < 1.6.0 - Authenticated Cross-Site Scripting (XSS) and XFS
Published Jun 1, 2021
·Updated
The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise its postexcerpt parameter before outputting it back in the shop/my-account/bello-listing-endpoint/ page, leading to a Cross-Site Scripting issue
Affected Software
1 affected component
Bold-themes Bello Wordpress<1.6.0
Event History
Jun 1, 2021
CVE Published
via MITRE·11:33 AM
Data Sourced
via MITRE·11:33 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-24319?
CVE-2021-24319 has a medium severity rating due to its potential for Cross-Site Scripting attacks.
2
How do I fix CVE-2021-24319?
To fix CVE-2021-24319, update the Bello - Directory & Listing WordPress theme to version 1.6.0 or higher.
3
What type of vulnerability is CVE-2021-24319?
CVE-2021-24319 is a Cross-Site Scripting vulnerability caused by improper input sanitization.
4
Which versions of the Bello theme are affected by CVE-2021-24319?
CVE-2021-24319 affects versions of the Bello theme prior to 1.6.0.
5
Where does CVE-2021-24319 impact users on the Bello theme?
CVE-2021-24319 impacts the shop/my-account/bello-listing-endpoint/ page of the Bello theme.