CVE-2021-24319

CVE-2021-24319: Bello < 1.6.0 - Authenticated Cross-Site Scripting (XSS) and XFS

Vendor Boldthemes
Product Bello - Directory & Listing
Weakness CWE-79 · XSS
Published June 1, 2021
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise its post_excerpt parameter before outputting it back in the shop/my-account/bello-listing-endpoint/ page, leading to a Cross-Site Scripting issue

Key dates

02Disclosure timeline

June 1, 2021 CVE published
August 3, 2024 Record updated

Related vulnerabilities

04Related CVE