The plugin contains a Missing Authorization vulnerability due to a missing capability check in the google_business_reviews_rating_admin_ajax AJAX action, which makes it possible for authenticated attackers with a role as low as subscriber to update plugin settings.