Feed/CVE-2026-77133
CVE-2026-77133

CVE-2026-77133

Published Aug 25, 2026·Updated Aug 25, 2026

NVD Description

The extension fails to restrict which frontend usergroups a logged-in user may assign to their own account when the profile edit plugin uses its default field configuration, allowing self-service privilege escalation into arbitrary frontend groups.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free