WordPress 15Zine before 3.3.0 is vulnerable to reflected cross-site scripting because the theme does not sanitize the cbi parameter before including it in the HTTP response via the cb_s_a AJAX action.
id: CVE-2020-36510
info:
name: WordPress 15Zine <3.3.0 - Cross-Site Scripting
author: veshraj
...