
🚨*CVE* CVE-2026-9676 The F4 Post Tree WordPress plugin before 2.0.5 does not perform capability checks or CSRF/nonce verification on one of its AJAX actions, allowing authenticated users wi… https://www.cve.org/CVERecord?id=CVE-2026-9676 ----- Traducción: CVE-2026-9676 El … http://infoflow.cloud`
Post summary
The message announces the discovery of CVE‑2026‑9676, explaining a missing capability check and CSRF/nonce verification in a WordPress plugin’s AJAX action.


