WordPress Pro Real Estate 7 theme before 3.1.1 contains a reflected cross-site scripting vulnerability. It does not properly sanitize the ct_community parameter in its search listing page before outputting it back.
View the template here CVE-2021-24387.yaml
References:
https://github.com/ARPSyndicate/cvemon