WordPress FoodBakery before 2.2 contains an unauthenticated reflected cross-site scripting vulnerability. It does not properly sanitize the foodbakery_radius parameter before outputting it back in the response.
id: CVE-2021-24389
info:
name: WordPress FoodBakery <2.2 - Cross-Site Scripting
author: daffain
...