The MapPress Maps for WordPress plugin has a security vulnerability in all versions up to 2.94.9. This allows attackers with administrator-level permissions to add harmful code to web pages that will run when a user opens the page. This only affects certain types of WordPress installations.