An XSS issue exists in the Laborator Neon theme 2.0 for WordPress via the data/autosuggest-remote.php q parameter.
laborator neon 2.0