WordPress Mediumish theme 1.0.47 and prior contains an unauthenticated reflected cross-site scripting vulnerability. The 's' GET parameter is not properly sanitized by the search feature before it is output back on the page.
id: CVE-2021-24316
info:
name: WordPress Mediumish Theme <=1.0.47 - Cross-Site Scripting
author
...