Impact
The Table Field Add‑on for ACF and SCF allows a stored cross‑site scripting attack through content added to individual cells of a table. Unsanitized input is stored and later rendered in page output without proper escaping, giving an attacker who can create or edit tables the ability to inject arbitrary JavaScript. Because the code runs in the context of any user who views the affected page, an attacker could steal session cookies, modify page content, redirect users, or perform other malicious actions against site visitors.
Affected Systems
WordPress sites that use the Table Field Add‑on for ACF and SCF supplied by the vendor jonua. All plugin releases up to and including version 1.3.35 are affected. Sites running version 1.4.0 or newer are not vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.4, indicating a moderate severity. No EPSS score is provided, so the likelihood of exploitation is uncertain, and the issue is not listed in the CISA KEV catalog. Exploitation requires that the attacker hold a contributor‑level or higher role on the WordPress installation, enabling table content creation or editing. Once malicious content is injected, it is displayed to all users visiting the page, allowing the attacker to compromise the confidentiality and integrity of the site’s web pages. The attack vector is via the web application’s content management interface, and the change is locally propagated but results in cross‑site script execution externally.
OpenCVE Enrichment