Wordpress Gwyn’s Imagemap Selector plugin 0.3.3 and prior contains a reflected cross-site scripting vulnerability. It does not sanitize the id and class parameters before returning them back in attributes.
View the template here CVE-2022-1221.yaml
References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1221