---
id: CVE-2026-15262
title: >-
  The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not
  escape Advanced Custom Fields values before outputting them in the WordPress
  admin list-table columns, allowing users with contributor-level access or
  above to stor…
summary: >-
  The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not
  escape Advanced Custom Fields values before outputting them in the WordPress
  admin list-table columns, allowing users with contributor-level access or
  above to stor…
severity: none
published: '2026-08-01'
updated: '2026-08-01'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15262'
references:
  - url: 'https://wpscan.com/vulnerability/dea1f3a9-2681-47a6-9e36-9d6ea799decb/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00129
epssPercentile: 0.0291
ingestedAt: '2026-08-02T05:17:47.655Z'
---

## Overview

The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fields values before outputting them in the WordPress admin list-table columns, allowing users with contributor-level access or above to store a payload that executes as JavaScript in the session of higher-privileged users who view the affected post-list screen.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
