CVE-2026-9676: Unknown f4 Post Tree
Medium severity, CVSS 4.3. EPSS: 0.1% chance of exploitation in the next 30 days.
The F4 Post Tree WordPress plugin before 2.0.5 does not perform capability checks or CSRF/nonce verification on one of its AJAX actions, allowing authenticated users with Subscriber-level access and above to modify the parent and menu order of arbitrary posts.
Affected products
- Unknown f4 Post Tree: before 2.0.5 (fixed in 2.0.5)
Published 2026-06-29. Last modified 2026-06-29.