The Wordpress plugin Code Snippets before 2.14.3 does not escape the snippets-safe-mode parameter before reflecting it in attributes, leading to a reflected cross-site scripting issue.
View the template here CVE-2021-25008.yaml
References:
https://wpscan.com/vulnerability/cb232354-f74d-48bb-b437-7bdddd1df42a