CVE-2026-9676
EUVD-2026-4004029.06.2026, 07:16
The F4 Post Tree WordPress plugin before 2.0.5 does not perform capability checks or CSRF/nonce verification on one of its AJAX actions, allowing authenticated users with Subscriber-level access and above to modify the parent and menu order of arbitrary posts.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.