The Snazzy Maps plugin prior to 1.1.5 for WordPress has XSS via the text or tab parameter.
atmist snazzy maps