Stored Cross-Site Scripting in ACF and SCF Plugin for WordPress
CVE-2026-78068

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
10 October 2026

What is CVE-2026-78068?

The ACF and SCF plugin has a vulnerability due to improper input sanitization and output escaping in the Table Field Add-on, allowing attackers with Contributor-level access and above to inject malicious scripts into page content. This can compromise user security, as the injected scripts will execute for any users who access the compromised pages, leading to potential data theft or site manipulation.

Affected Version(s)

Table Field Add-on for ACF and SCF 0 <= 1.3.35

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Omar Elshopky (3l5h0pky)
.