The plugin contains a Missing Authorization vulnerability due to an incorrect capability check in the wo_remove_client AJAX action, which makes it possible for authenticated attackers with a role as low as subscriber to delete arbitrary client.