WordPress Under Construction plugin before 1.19 contains a cross-site scripting vulnerability. The plugin echoes out the raw value of `$GLOBALS['PHP_SELF']` in the ucOptions.php file on certain configurations, including Apache+modPHP.
id: CVE-2021-39320
info:
name: WordPress Under Construction <1.19 - Cross-Site Scripting
author
...