Impact
The Table Field Add-on for ACF and SCF plugin for WordPress contains a stored cross‑site scripting flaw due to inadequate input sanitization and output escaping of table field values. The vulnerability enables an authenticated user with subscriber-level access or higher to inject JavaScript that executes whenever an affected page is viewed. This can lead to session hijacking, theft of sensitive data, defacement, or delivery of malware to site visitors.
Affected Systems
The flaw exists in all releases of the plugin up to and including version 1.4.1‑RC2. The affected product is jonua's Table Field Add‑on for Advanced Custom Fields and Static Custom Fields (ACF and SCF).
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog. Attackers must obtain authenticated access at the subscriber level or above, then submit malicious input through the table field interface. Once stored, the malicious scripts trigger on page load and can compromise any visitor or user with sufficient privileges to view the affected content. The lack of publicly documented exploit code suggests a lower exploitation probability, but the impact remains serious for sites that rely on the plugin for content management.
OpenCVE Enrichment