The plugin is dependent on a vulnerable version of `next`. Versions from 9.5.5 - 14.2.14 are vulnerable to an authorization vulnerability. The plugin currently uses `next` ^13.1.1. See https://github.com/advisories/GHSA-7gfc-8cq8-jh5f.