Table Field Add-on for ACF and SCF <= 1.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Table Field Value
- ID
- WPSEC-2026-0636
- Plugin
- Table Field Add-on for ACF and SCF (advanced-custom-fields-table-field)
- Affected
- from 1.3.0 before 1.4.1
- Remediation
- Update to 1.4.1 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Weakness
- CWE-79
- Usage
- Plugin Medium · Affected versions Low among sites WPSec scans, 2026-10-08
- Attack surface
- Table Field Add-on for ACF and SCF on WPSec AttackSurface
- Fix released
- Published
Description
The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the table field value in versions 1.3.0 up to, and including, 1.4.0. The plugin accepts and stores submitted field values that are not table objects without sanitizing them, and prints such stored values without escaping into the table field's edit form. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts that will execute whenever a user, such as an editor or administrator, opens the edit screen of a post containing the injected field.
References
- https://wpsec.com/vuln/WPSEC-2026-0636/
- https://plugins.svn.wordpress.org/advanced-custom-fields-table-field/tags/1.4.1/
- https://wordpress.org/plugins/advanced-custom-fields-table-field/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS