๐Ÿ” CVE Alert

CVE-2026-9676

UNKNOWN 0.0

f4 Post Tree < 2.0.5 - Subscriber+ Arbitrary Post Parent/Menu Order Modification

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The F4 Post Tree WordPress plugin before 2.0.5 does not perform capability checks or CSRF/nonce verification on one of its AJAX actions, allowing authenticated users with Subscriber-level access and above to modify the parent and menu order of arbitrary posts.

Vendor unknown
Product f4 post tree
Published Jun 29, 2026
Stay Ahead of the Next One

Get instant alerts for unknown f4 post tree

Be the first to know when new unknown vulnerabilities affecting unknown f4 post tree are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / F4 Post Tree
0 < 2.0.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/54627b10-115c-4434-a17b-eb680244889f/

Credits

Mustafa Ahmed WPScan