WordPress Skaut Bazar plugin before 1.3.3 contains a reflected cross-site scripting vulnerability due to the use of $_SERVER['PHP_SELF'] in the ~/skaut-bazar.php file, which allows attackers to inject arbitrary web scripts.
id: CVE-2021-34643
info:
name: WordPress Skaut Bazar <1.3.3 - Cross-Site Scripting
author: dhiy
...