CyberRota Analysis
AI-GeneratedThe vulnerability allows logged-in users to assign themselves to arbitrary frontend user groups due to inadequate restrictions in the profile edit plugin's default configuration. This can lead to self-service privilege escalation, potentially compromising user permissions and access controls. Organizations utilizing this extension should prioritize remediation to prevent unauthorized access and maintain proper user group management.
Original NVD Description
The extension fails to restrict which frontend usergroups a logged-in user may assign to their own account when the profile edit plugin uses its default field configuration, allowing self-service privilege escalation into arbitrary frontend groups.