Php-mod/curl library before 2.3.2 contains a cross-site scripting vulnerability via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php. An attacker can inject arbitrary script, which can allow theft of cookie-based authentication credentials and launch of other attacks.
View the template here CVE-2021-30134.yaml
References:
https://wpscan.com/vulnerability/0b547728-27d2-402e-ae17-90d539344ec7