Thème WordPress
Vulnérabilités Bello – Directory & Listing
Cette page rassemble les failles publiées pour Bello – Directory & Listing, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Bello – Directory & Listing
3 fiches
Bello – Directory & Listing – < 1.6.0 – Cross-Site Scripting
The Bello – Directory & Listing WordPress theme before 1.6.0 did not properly sanitise its post_excerpt parameter before outputting it back in the shop/my-account/bello-listing-endpoint/ page, leading to a Cross-Site Scripting issue
[*, 1.6.0)
1.6.0
16/05/2021
Bello – Directory & Listing <= 1.5.9 – Unauthenticated SQL Injection
The Bello – Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt_bb_listing_field_now_open, bt_bb_listing_field_my_lng, listing_list_view and bt_bb_listing_field_my_lat parameters before using them in a SQL statement, leading to SQL Injection issues.
[*, 1.6.0)
1.6.0
16/05/2021
Directory & Listing < 1.6.0 – Reflected Cross-Site Scripting
The Bello – Directory & Listing WordPress theme before 1.6.0 did not properly sanitise and escape its listing_list_view, bt_bb_listing_field_my_lat, bt_bb_listing_field_my_lng, bt_bb_listing_field_distance_value, bt_bb_listing_field_my_lat_default, bt_bb_listing_field_keyword, bt_bb_listing_field_location_autocomplete, bt_bb_listing_field_price_range_from and bt_bb_listing_field_price_range_to parameters in its listing page, leading to reflected Cross-Site Scripting issues.
[*, 1.6.0)
1.6.0
21/03/2021
Thèmes également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.