The MapPress Maps for WordPress plugin is vulnerable to a security threat called Stored Cross-Site Scripting. This means that if someone with contributor-level or higher permissions uses the plugin, they can inject malicious web scripts into a page. When a user visits this page, the script will execute. This vulnerability affects all versions of the plugin up to, and including, 2.88.4.