The MapPress Maps for WordPress plugin has a security issue called Stored Cross-Site Scripting that affects all versions up to 2.94.1. This allows attackers with contributor-level access or higher to add harmful web scripts into pages that will run whenever someone views that page.