WordPress Supsystic Ultimate Maps plugin before 1.2.5 contains an unauthenticated reflected cross-site scripting vulnerability due to improper sanitization of the tab parameter on the options page before outputting it in an attribute.
id: CVE-2021-24274
info:
name: WordPress Supsystic Ultimate Maps <1.2.5 - Cross-Site Scripting
...