Product
Authenticated attackers can perform CBC bit-flipping attacks on the Frontend Admin plugin to reset arbitrary user passwords, enabling full site compromise.