Executive brief
The F4 Post Tree plugin for WordPress, which helps manage website content hierarchy, contains a security flaw that allows low-level users to reorganize website pages. An authenticated user, such as a subscriber, can change the parent-child relationship and display order of posts or pages without permission. This could lead to unauthorized changes in website structure and navigation, potentially disrupting the user experience or misrepresenting site content.
Technical details
The vulnerability is a missing authorization check (CWE-862) and missing CSRF protection in the 'f4_tree_move_post' AJAX action. The plugin fails to verify if the requesting user has the appropriate permissions or a valid security nonce before processing hierarchy updates. An attacker with at least Subscriber-level authentication can send a crafted POST request to wp-admin/admin-ajax.php to modify the 'post_parent' and 'menu_order' attributes of any post or page. This allows for unauthorized modification of the site's content structure. The issue is fixed in version 2.0.5.
Affected products
- F4 Works F4 Post Tree < 2.0.5
Timeline
- 2026-06-08: disclosed: Publicly published via WPScan
- 2026-06-29: advisory: NVD publication date