{
 "id": "WPSEC-2026-0636",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0636/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0636/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0636/index.md",
 "title": "Table Field Add-on for ACF and SCF <= 1.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Table Field Value",
 "description": "The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the table field value in versions 1.3.0 up to, and including, 1.4.0. The plugin accepts and stores submitted field values that are not table objects without sanitizing them, and prints such stored values without escaping into the table field's edit form. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts that will execute whenever a user, such as an editor or administrator, opens the edit screen of a post containing the injected field.",
 "plugin": {
  "slug": "advanced-custom-fields-table-field",
  "name": "Table Field Add-on for ACF and SCF",
  "full_name": "Table Field Add-on for ACF and SCF",
  "wordpress_org": "https://wordpress.org/plugins/advanced-custom-fields-table-field/",
  "advisories_url": "https://wpsec.com/vuln/plugin/advanced-custom-fields-table-field/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/advanced-custom-fields-table-field"
 },
 "type": "XSS",
 "cwe": [
  "CWE-79"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 6.4,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "1.3.0",
    "from_inclusive": true,
    "to": "1.4.1",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 1.3.0 before 1.4.1"
  ]
 },
 "introduced_in": "1.3.0",
 "fixed_in": "1.4.1",
 "remediation": "Update to 1.4.1 or later.",
 "fix_released": "2026-10-07T09:52:54+00:00",
 "published": "2026-10-08T10:46:37+00:00",
 "updated": "2026-10-07T12:20:04.907256+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0636/",
  "https://plugins.svn.wordpress.org/advanced-custom-fields-table-field/tags/1.4.1/",
  "https://wordpress.org/plugins/advanced-custom-fields-table-field/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/advanced-custom-fields-table-field",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Low",
  "as_of": "2026-10-08"
 }
}