Table Field Add-on for ACF and SCF <= 1.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Table Field Value

Medium 6.4 CWE-79Fixed in 1.4.1
ID
WPSEC-2026-0636
Plugin
Table Field Add-on for ACF and SCF (advanced-custom-fields-table-field)
Affected
from 1.3.0 before 1.4.1
Remediation
Update to 1.4.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Weakness
CWE-79
Usage
Plugin Medium · Affected versions Low among sites WPSec scans, 2026-10-08
Attack surface
Table Field Add-on for ACF and SCF on WPSec AttackSurface
Fix released
Published

Description

The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the table field value in versions 1.3.0 up to, and including, 1.4.0. The plugin accepts and stores submitted field values that are not table objects without sanitizing them, and prints such stored values without escaping into the table field's edit form. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts that will execute whenever a user, such as an editor or administrator, opens the edit screen of a post containing the injected field.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0