# Table Field Add-on for ACF and SCF <= 1.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Table Field Value

- **ID:** WPSEC-2026-0636
- **Plugin:** Table Field Add-on for ACF and SCF (`advanced-custom-fields-table-field`), https://wordpress.org/plugins/advanced-custom-fields-table-field/
- **Affected versions:** from 1.3.0 before 1.4.1
- **Fixed in:** 1.4.1 (Update to 1.4.1 or later.)
- **Severity:** Medium 6.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N)
- **Weakness:** CWE-79
- **Usage among sites WPSec scans:** plugin Medium, affected versions Low (as of 2026-10-08)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/advanced-custom-fields-table-field
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0636/

## Description

The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the table field value in versions 1.3.0 up to, and including, 1.4.0. The plugin accepts and stores submitted field values that are not table objects without sanitizing them, and prints such stored values without escaping into the table field's edit form. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts that will execute whenever a user, such as an editor or administrator, opens the edit screen of a post containing the injected field.

## References

- https://wpsec.com/vuln/WPSEC-2026-0636/
- https://plugins.svn.wordpress.org/advanced-custom-fields-table-field/tags/1.4.1/
- https://wordpress.org/plugins/advanced-custom-fields-table-field/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0636/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
