WordPress Jannah theme before 5.4.5 contains a reflected cross-site scripting vulnerability. It does not properly sanitize the ‘query’ POST parameter in its tie_ajax_search AJAX action.
View the template here CVE-2021-24407.yaml
References:
https://wpscan.com/vulnerability/fba9f010-1202-4eea-a6f5-78865c084153