Description
The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Table Field Value in all versions up to, and including, 1.4.1-RC2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-10-10
Score: 6.4 Medium
EPSS: n/a
KEV: No
Impact: Stored Cross-Site Scripting
Action: Patch
AI Analysis

Impact

The Table Field Add-on for ACF and SCF plugin for WordPress contains a stored cross‑site scripting flaw due to inadequate input sanitization and output escaping of table field values. The vulnerability enables an authenticated user with subscriber-level access or higher to inject JavaScript that executes whenever an affected page is viewed. This can lead to session hijacking, theft of sensitive data, defacement, or delivery of malware to site visitors.

Affected Systems

The flaw exists in all releases of the plugin up to and including version 1.4.1‑RC2. The affected product is jonua's Table Field Add‑on for Advanced Custom Fields and Static Custom Fields (ACF and SCF).

Risk and Exploitability

The CVSS score of 6.4 indicates a moderate severity. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog. Attackers must obtain authenticated access at the subscriber level or above, then submit malicious input through the table field interface. Once stored, the malicious scripts trigger on page load and can compromise any visitor or user with sufficient privileges to view the affected content. The lack of publicly documented exploit code suggests a lower exploitation probability, but the impact remains serious for sites that rely on the plugin for content management.

Generated by OpenCVE AI on October 10, 2026 at 04:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Table Field Add‑on to a version newer than 1.4.1‑RC2, which removes the stored XSS flaw.
  • Verify that the plugin correctly sanitizes and escapes all table field inputs; if an update is not feasible, implement server‑side filtering of input characters such as <, >, and " before storage.
  • Restrict subscriber-level users from accessing or modifying table fields unless necessary by adjusting role capabilities or moving them to a higher privilege level.
  • Deploy a Content Security Policy that disallows inline scripts and restricts script sources to trusted origins to mitigate the effects of any remaining XSS vulnerabilities.

Generated by OpenCVE AI on October 10, 2026 at 04:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 03:45:00 +0000

Type Values Removed Values Added
Description The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Table Field Value in all versions up to, and including, 1.4.1-RC2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Table Field Add-on for ACF and SCF <= 1.4.1-RC2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Table Field Value
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T03:26:44.188Z

Reserved: 2026-09-23T15:45:04.412Z

Link: CVE-2026-96743

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T04:18:20.080

Modified: 2026-10-10T04:18:20.080

Link: CVE-2026-96743

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T04:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')