WordPress FoodBakery before 2.2 contains an unauthenticated reflected cross-site scripting vulnerability. It does not properly sanitize the foodbakery_radius parameter before outputting it back in the response.
View the template here CVE-2021-24389.yaml
References:
https://github.com/ARPSyndicate/cvemon