The data/autosuggest-remote.php q parameter in the Laborator Neon theme 2.0 for WordPress was found to have an XSS vulnerability.
data/autosuggest-remote.php