Plate media plugins has a XSS in media embed element when using custom URL parsers (CVE-2024-40631) | HOL Guard CVE