Stored Cross-Site Scripting in ACF and SCF Plugin for WordPress
CVE-2026-78068
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-78068?
The ACF and SCF plugin has a vulnerability due to improper input sanitization and output escaping in the Table Field Add-on, allowing attackers with Contributor-level access and above to inject malicious scripts into page content. This can compromise user security, as the injected scripts will execute for any users who access the compromised pages, leading to potential data theft or site manipulation.
Affected Version(s)
Table Field Add-on for ACF and SCF 0 <= 1.3.35