CVE-2026-9676Disclosure

LOWCVSS 4.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The F4 Post Tree WordPress plugin before 2.0.5 does not perform capability checks or CSRF/nonce verification on one of its AJAX actions, allowing authenticated users with Subscriber-level access and above to modify the parent and menu order of arbitrary posts.

0.0/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-29: 3Technical Details · 2026-06-29: 306-29
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-9676 The F4 Post Tree WordPress plugin before 2.0.5 does not perform capability checks or CSRF/nonce verification on one of its AJAX actions, allowing authenticated users wi… https://www.cve.org/CVERecord?id=CVE-2026-9676 ----- Traducción: CVE-2026-9676 El … http://infoflow.cloud`

    Post summary

    The message announces the discovery of CVE‑2026‑9676, explaining a missing capability check and CSRF/nonce verification in a WordPress plugin’s AJAX action.

    0001049
    89 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-9676 Unauthorized Post Modification via AJAX in F4 Post Tree WordPress Plugin Before 2.0.5 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-9676

    Post summary

    A brief disclosure of CVE-2026-9676 indicates an unauthorized post modification flaw via AJAX in the F4 Post Tree WordPress Plugin (pre‑2.0.5), with only minimal technical details provided.

    00010189
    4.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-9676 The F4 Post Tree WordPress plugin before 2.0.5 does not perform capability checks or CSRF/nonce verification on one of its AJAX actions, allowing authenticated users wi… https://www.cve.org/CVERecord?id=CVE-2026-9676

    Post summary

    The CVE-2026-9676 disclosure notes missing capability checks and CSRF/nonce verification in the F4 Post Tree WordPress plugin’s AJAX action, but provides no evidence of exploitation, patches, or PoC.

    00000719
    57.7K followersView on X

Explore more