The Wordpress plugin Code Snippets before 2.14.3 does not escape the snippets-safe-mode parameter before reflecting it in attributes, leading to a reflected cross-site scripting issue.
id: CVE-2021-25008
info:
name: The Code Snippets WordPress Plugin < 2.14.3 - Cross-Site Scripting
...