WordPress Jannah theme before 5.4.4 contains a reflected cross-site scripting vulnerability. It does not properly sanitize the options JSON parameter in its tie_get_user_weather AJAX action before outputting it back in the page.
View the template here CVE-2021-24364.yaml
References:
https://github.com/ARPSyndicate/cvemon