Stored Cross-Site Scripting Vulnerability in ACF and SCF Table Field Add-on for WordPress
CVE-2026-96743

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
10 October 2026

What is CVE-2026-96743?

The ACF and SCF Table Field Add-on for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping. Authenticated attackers with subscriber-level access or higher can exploit this vulnerability by injecting arbitrary scripts into Table Field Values. This malicious code execution occurs when users access affected pages, potentially compromising user sessions and data integrity.

Affected Version(s)

Table Field Add-on for ACF and SCF 0 <= 1.4.1-RC2

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kuba
.