The MapPress Maps for WordPress plugin for WordPress is vulnerable to a security issue called Stored Cross-Site Scripting. This vulnerability affects all versions of the plugin up to and including version 2.88.13. An attacker with contributor access or higher can inject malicious code into pages on the website. Whenever a user visits one of these pages, the malicious code will execute. This could be used to access sensitive information or take control of a user’s account. To protect yourself, make sure you have the latest version of the plugin installed.