Bitbucket Approve

The Jenkins project announced an unresolved security vulnerability affecting the current version of this plugin (why?):
List of issues
JENKINS-60989 bitbucket-approve-plugin, add support for pipeline
JENKINS-53852A way to provide url of jenkins where to approve. Now a fixed "" is used
JENKINS-53850Could we have a possibility to provide url of bitbucket to use via setting. Now the plugin uses a fixed "" url is used.
JENKINS-46681Failure in case of approved commit
JENKINS-40727incorrect revision hash used in approving bitbucket commit when pre build merge is enabled
JENKINS-27020integrate credentials plugin