WordPress Jannah theme before 5.4.4 contains a reflected cross-site scripting vulnerability. It does not properly sanitize the options JSON parameter in its tie_get_user_weather AJAX action before outputting it back in the page.
id: CVE-2021-24364
info:
name: WordPress Jannah Theme <5.4.4 - Cross-Site Scripting
author: pik
...