The extension fails to restrict which frontend usergroups a logged-in user may assign to their own account when the profile edit plugin uses its default field configuration, allowing self-service privilege escalation into arbitrary frontend groups.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-25 09:17
Updated : 2026-08-26 17:13
NVD link : CVE-2026-77133
Mitre link : CVE-2026-77133
CVE.ORG link : CVE-2026-77133
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
