WordPress 15Zine before 3.3.0 is vulnerable to reflected cross-site scripting because the theme does not sanitize the cbi parameter before including it in the HTTP response via the cb_s_a AJAX action.
View the template here CVE-2020-36510.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2020-36510