The OpenStreetMap plugin for WordPress, specifically for the Gutenberg and WPBakery Page Builder, is at risk of a security issue called Stored Cross-Site Scripting. This is because the plugin does not properly filter and protect the input and output of information. This means that someone with contributor-level access or higher could potentially insert harmful code into a page, which would then run whenever someone views that page.