CVE-2026-9676: Unknown f4 Post Tree

Medium severity, CVSS 4.3. EPSS: 0.1% chance of exploitation in the next 30 days.

The F4 Post Tree WordPress plugin before 2.0.5 does not perform capability checks or CSRF/nonce verification on one of its AJAX actions, allowing authenticated users with Subscriber-level access and above to modify the parent and menu order of arbitrary posts.

Affected products

  • Unknown f4 Post Tree: before 2.0.5 (fixed in 2.0.5)

Published 2026-06-29. Last modified 2026-06-29.