WordPress Plotly 1.0.2 Cross Site Scripting

WordPress Plotly plugin version 1.0.2 suffers from a persistent cross site scripting vulnerability.