Wordpress Gwyn's Imagemap Selector plugin 0.3.3 and prior contains a reflected cross-site scripting vulnerability. It does not sanitize the id and class parameters before returning them back in attributes.
id: CVE-2022-1221
info:
name: WordPress Gwyn's Imagemap Selector <=0.3.3 - Cross-Site Scripting
...