A popular plugin called Frontend Admin for WordPress is at risk for a type of cyber attack called SQL Injection. This is because it does not properly protect against user input and does not properly prepare the database for queries. This could allow attackers to access private information from the database. To perform this attack, the attacker would need to have access to view form submissions and have the form submission code added to a page.