CPE
An unauthenticated account takeover vulnerability exists in the fof/oauth extension due to improper validation of unverified email addresses returned by the Discord OAuth provider, allowing attackers to hijack existing Flarum accounts.