Cross-site scripting (XSS) vulnerability in map/map.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/72384
http://wordpress.org/extend/plugins/count-per-day/changelog/
http://secunia.com/advisories/47529
http://plugins.trac.wordpress.org/changeset/488883/count-per-day