Vulnerability in Table Field Add-on for ACF and SCF — CVE-2026-96743
MediumSeverity
—Estimated exploit probability
50,000+ sitesInstalls
1.4.1Fixed in
What to do now
Update Table Field Add-on for ACF and SCF to 1.4.1 or later.
Affected versions
- Everything up to and including 1.4.1-RC2
Affected: Table Field Add-on for ACF and SCF (plugin, advanced-custom-fields-table-field)
What the vulnerability is
The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Table Field Value in all versions up to, and including, 1.4.1-RC2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.