This plugin is vulnerable to XSS -- try entering <script>alert('boom');</script> in the input field of the example.
But yes, I should really add a flag to strip out any script elements :)
<table style="background-image:url(javascript:alert(1))"><tr><td>Hi</td></tr></table>
However, read debt's comment below. XSS is irrelevant here since "XSS" means cross-site scripting, i.e., ,managing to embed Javascript into pages someone ELSE sees. Only the client sees this, it doesn't get reproduced for anyone else.