WordPress Skaut Bazar plugin before 1.3.3 contains a reflected cross-site scripting vulnerability due to the use of $_SERVER[‘PHP_SELF’] in the ~/skaut-bazar.php file, which allows attackers to inject arbitrary web scripts.
View the template here CVE-2021-34643.yaml
References:
https://github.com/ARPSyndicate/cvemon