The MapPress Maps for WordPress plugin has a security issue called Stored Cross-Site Scripting. This problem affects all versions up to and including 2.94.8 because it does not properly clean and protect the information it receives and displays. This allows attackers who are logged in as Contributors or higher to add harmful web scripts to pages that will activate whenever someone visits the page.