Vulnerability record · CVE-2021-24321 · published 1 June 2021
CVE-2021-24321: Bello WordPress theme unauthenticated SQL injection via listing parameters
Bold Themes · Bello
The Bello - Directory & Listing WordPress theme before 1.6.0 passes several listing-related parameters (bt_bb_listing_field_price_range_to, bt_bb_listing_field_now_open, bt_bb_listing_field_my_lng, listing_list_view, bt_bb_listing_field_my_lat) into SQL statements without sanitisation, creating a SQL injection flaw. Because the parameters are reachable without authentication, any remote visitor can attempt to inject SQL against the site's database.
Description
The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt_bb_listing_field_now_open, bt_bb_listing_field_my_lng, listing_list_view and bt_bb_listing_field_my_lat parameters before using them in a SQL statement, leading to SQL Injection issues
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, public exploit references and a very high EPSS score make this an urgent patch target.
What it is
The Bello - Directory & Listing WordPress theme before 1.6.0 passes several listing-related parameters (bt_bb_listing_field_price_range_to, bt_bb_listing_field_now_open, bt_bb_listing_field_my_lng, listing_list_view, bt_bb_listing_field_my_lat) into SQL statements without sanitisation, creating a SQL injection flaw. Because the parameters are reachable without authentication, any remote visitor can attempt to inject SQL against the site's database.
Impact
An attacker can read, modify or delete database contents, including WordPress user credentials and listing data, and may be able to escalate to full site compromise depending on database privileges.
Attack surface
Reached over the network through HTTP requests to the theme's listing functionality, with no authentication or user interaction required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). The exact endpoint and parameter placement are not detailed in the record beyond the named parameters.
Exploitation
No CISA KEV listing and no ransomware association are recorded, but EPSS is high (0.66576, 99.25th percentile) and both references are tagged Exploit, indicating public exploit material exists.
What to do
- Update the Bello theme to version 1.6.0 or later, which is the fixed release per the description.
- If immediate patching is not possible, disable or remove the theme until it can be updated.
- Apply a web application firewall rule to block SQL injection patterns targeting the named listing parameters.
- Review database accounts used by WordPress for least privilege to limit damage from successful injection.
- Audit the site for signs of prior compromise before and after patching.
Detection
- Search web server and WAF logs for requests containing the parameters bt_bb_listing_field_price_range_to, bt_bb_listing_field_now_open, bt_bb_listing_field_my_lng, bt_bb_listing_field_my_lat and listing_list_view with SQL metacharacters.
- Monitor database query logs for anomalous or malformed SQL originating from the WordPress application.
- Check for unexpected changes to WordPress users, options or listing content that could indicate successful exploitation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://m0ze.ru/vulnerability/%5B2021-03-21%5D-%5BWordPress%5D-%5BCWE-89%5D-Bello-WordPress-Theme-v1.5.9.txt | ExploitThird Party Advisory |
| https://wpscan.com/vulnerability/7314f9fa-c047-4e0c-b145-940240a50c02 | ExploitThird Party Advisory |
| https://m0ze.ru/vulnerability/%5B2021-03-21%5D-%5BWordPress%5D-%5BCWE-89%5D-Bello-WordPress-Theme-v1.5.9.txt | ExploitThird Party Advisory |
| https://wpscan.com/vulnerability/7314f9fa-c047-4e0c-b145-940240a50c02 | ExploitThird Party Advisory |
Track CVE-2021-24321 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-24321), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.