Junglewise Threat Intelligence

CVE-2026-9676: F4 Post Tree missing authorization in f4_tree_move_post AJAX action

CVE-2026-9676 · Severity: info · CVSS 4.3 · Published 2026-06-29

Executive brief

The F4 Post Tree plugin for WordPress, which helps manage website content hierarchy, contains a security flaw that allows low-level users to reorganize website pages. An authenticated user, such as a subscriber, can change the parent-child relationship and display order of posts or pages without permission. This could lead to unauthorized changes in website structure and navigation, potentially disrupting the user experience or misrepresenting site content.

Technical details

The vulnerability is a missing authorization check (CWE-862) and missing CSRF protection in the 'f4_tree_move_post' AJAX action. The plugin fails to verify if the requesting user has the appropriate permissions or a valid security nonce before processing hierarchy updates. An attacker with at least Subscriber-level authentication can send a crafted POST request to wp-admin/admin-ajax.php to modify the 'post_parent' and 'menu_order' attributes of any post or page. This allows for unauthorized modification of the site's content structure. The issue is fixed in version 2.0.5.

Affected products

  • F4 Works F4 Post Tree < 2.0.5

Timeline

  • 2026-06-08: disclosed: Publicly published via WPScan
  • 2026-06-29: advisory: NVD publication date

References