WordPress Jannah theme before 5.4.5 contains a reflected cross-site scripting vulnerability. It does not properly sanitize the 'query' POST parameter in its tie_ajax_search AJAX action.
id: CVE-2021-24407
info:
name: WordPress Jannah Theme <5.4.5 - Cross-Site Scripting
author: pik
...