From Derek:
There is an issue when processing plugin tags such as "<<font color=blue>>" in that the plugin details are not 'sanitized' and this could let through some naughty, but probably harmless, code into the HTML output.