The vulnerability exists due to the plugin failing to validate the aud (audience) claim in ID tokens during authentication, which could potentially allow attackers use of a token with a mismatched or malicious aud claim to bypass authentication controls.