← Vulnerability feed

Vulnerability record · CVE-2021-24321 · published 1 June 2021

CVE-2021-24321: Bello WordPress theme unauthenticated SQL injection via listing parameters

Bold Themes · Bello

The Bello - Directory & Listing WordPress theme before 1.6.0 passes several listing-related parameters (bt_bb_listing_field_price_range_to, bt_bb_listing_field_now_open, bt_bb_listing_field_my_lng, listing_list_view, bt_bb_listing_field_my_lat) into SQL statements without sanitisation, creating a SQL injection flaw. Because the parameters are reachable without authentication, any remote visitor can attempt to inject SQL against the site's database.

9.8 CVSS 3.1 Critical EPSS 67% · top 0.7% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt_bb_listing_field_now_open, bt_bb_listing_field_my_lng, listing_list_view and bt_bb_listing_field_my_lat parameters before using them in a SQL statement, leading to SQL Injection issues

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required, public exploit references and a very high EPSS score make this an urgent patch target.

What it is

The Bello - Directory & Listing WordPress theme before 1.6.0 passes several listing-related parameters (bt_bb_listing_field_price_range_to, bt_bb_listing_field_now_open, bt_bb_listing_field_my_lng, listing_list_view, bt_bb_listing_field_my_lat) into SQL statements without sanitisation, creating a SQL injection flaw. Because the parameters are reachable without authentication, any remote visitor can attempt to inject SQL against the site's database.

Impact

An attacker can read, modify or delete database contents, including WordPress user credentials and listing data, and may be able to escalate to full site compromise depending on database privileges.

Attack surface

Reached over the network through HTTP requests to the theme's listing functionality, with no authentication or user interaction required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). The exact endpoint and parameter placement are not detailed in the record beyond the named parameters.

Exploitation

No CISA KEV listing and no ransomware association are recorded, but EPSS is high (0.66576, 99.25th percentile) and both references are tagged Exploit, indicating public exploit material exists.

What to do

  • Update the Bello theme to version 1.6.0 or later, which is the fixed release per the description.
  • If immediate patching is not possible, disable or remove the theme until it can be updated.
  • Apply a web application firewall rule to block SQL injection patterns targeting the named listing parameters.
  • Review database accounts used by WordPress for least privilege to limit damage from successful injection.
  • Audit the site for signs of prior compromise before and after patching.

Detection

  • Search web server and WAF logs for requests containing the parameters bt_bb_listing_field_price_range_to, bt_bb_listing_field_now_open, bt_bb_listing_field_my_lng, bt_bb_listing_field_my_lat and listing_list_view with SQL metacharacters.
  • Monitor database query logs for anomalous or malformed SQL originating from the WordPress application.
  • Check for unexpected changes to WordPress users, options or listing content that could indicate successful exploitation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-24321 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.1CVE-2021-24320Bold-themes bello cross-site scripting vulnerabilityThe Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise and escape its listing_list_view, bt_bb_listing_field_my_lat, …EPSS 11%5.4CVE-2021-24319Bold-themes bello cross-site scripting vulnerabilityThe Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise its post_excerpt parameter before outputting it back in the sh…EPSS 1.7%9.8CVE-2026-76461Cisco AsyncOS email parsing SQL injection allows root command executionCisco AsyncOS Software for Cisco Secure Email Gateway fails to properly validate email parsing input, allowing crafted email messages containing mali…KEVEPSS 28%analysed9.3CVE-2026-9586Sangoma Switchvox unauthenticated SQL injection in /pa endpointSangoma Switchvox SMB Edition 8.3 (104997) fails to sanitize the PhoneIP value from XML content beginning with <PolycomIPPhone> before concatenating …KEVEPSS 19%analysed10.0CVE-2026-72898Metabase unauthenticated SQL injection in reset_password endpointMetabase exposes a database endpoint, '/reset_password', that fails to neutralize attacker-supplied SQL, allowing arbitrary SQL injection. Because th…KEVEPSS 19%analysed5.9CVE-2026-60137WordPress WP_Query author__not_in SQL injectionWordPress core fails to properly sanitise the author__not_in parameter of WP_Query in versions before 6.8.6, 6.9.5 and 7.0.2, allowing SQL injection …KEVEPSS 5.9%analysed9.8CVE-2026-9082Drupal core SQL injection in unauthenticated request pathDrupal core contains a SQL injection flaw (CWE-89) caused by improper neutralization of special elements in SQL commands. It affects multiple core br…KEVEPSS 16%analysed9.3CVE-2026-42208LiteLLM proxy SQL injection in API key checkLiteLLM versions 1.81.16 to before 1.83.7 build a database query for proxy API key checks by concatenating the caller-supplied key into the query tex…KEVEPSS 5.8%analysed

Source: NIST National Vulnerability Database (record CVE-2021-24321), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.