WordPress Securimage-WP-Fixed plugin 3.5.4 and prior contains a cross-site scripting vulnerability due to the use of $_SERVER[‘PHP_SELF’] in the ~/securimage-wp.php file, which allows attackers to inject arbitrary web scripts.
View the template here CVE-2021-34640.yaml
References:
https://github.com/ARPSyndicate/cvemon