High 7.1
2025-01-13< 1.1.19
CVE-2025-22499
Minimum safe version
1.1.19
Update to 1.1.19 or later to address 5 fixable vulnerabilities
CVE-2025-22499
WordPress F4 Post Tree Plugin < 1.1.15 is vulnerable to Cross Site Scripting (XSS)
Unauthorised AJAX Calls via Freemius
WordPress F4 Post Tree plugin <= 1.1.8 - Sensitive Information Disclosure vulnerability
WordPress F4 Post Tree plugin <= 1.1.8 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability