CVE-2026-9676 PUBLISHED

f4 Post Tree < 2.0.5 - Subscriber+ Arbitrary Post Parent/Menu Order Modification

Assigner: WPScan
Reserved: 27.05.2026 Published: 29.06.2026 Updated: 29.06.2026

The F4 Post Tree WordPress plugin before 2.0.5 does not perform capability checks or CSRF/nonce verification on one of its AJAX actions, allowing authenticated users with Subscriber-level access and above to modify the parent and menu order of arbitrary posts.

Product Status

Vendor Unknown
Product F4 Post Tree
Versions Default: unaffected
  • affected from 0 to 2.0.5 (excl.)

Credits

  • Mustafa Ahmed finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE
  • CWE-352 Cross-Site Request Forgery (CSRF) CWE