WordPress Under Construction plugin before 1.19 contains a cross-site scripting vulnerability. The plugin echoes out the raw value of $GLOBALS['PHP_SELF']
in the ucOptions.php file on certain configurations, including Apache+modPHP.
View the template here CVE-2021-39320.yaml
References:
https://github.com/ARPSyndicate/cvemon