WordPress Plugin MapPress before version 2.73.4 does not sanitize and escape the ‘mapid’ parameter before outputting it back in the “Bad mapid” error message, leading to reflected cross-site scripting.
View the template here CVE-2022-0208.yaml
References:
https://github.com/ARPSyndicate/cvemon