---
id: CVE-2026-96743
title: >-
  The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to
  Stored Cross-Site Scripting via Table Field Value in all versions up to, and
  including, 1.4.1-RC2 due to insufficient input sanitization and output
  escaping
summary: >-
  The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to
  Stored Cross-Site Scripting via Table Field Value in all versions up to, and
  including, 1.4.1-RC2 due to insufficient input sanitization and output
  escaping. Th…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
published: '2026-10-10'
updated: '2026-10-10'
sourceUpdated: '2026-10-10T04:18:20.080'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-96743'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/advanced-custom-fields-table-field/tags/1.4.0/classes/Field.php#L275
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/advanced-custom-fields-table-field/tags/1.4.0/classes/Field.php#L463
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset/3732330/advanced-custom-fields-table-field/trunk/classes/Field.php
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?reponame=&new=3732282%40advanced-custom-fields-table-field%2Ftags%2F1.4.1&old=3696309%40advanced-custom-fields-table-field%2Ftags%2F1.4.1-RC2
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/2656ae60-0658-4230-99fc-9a754a4f61bf?source=cve
    label: security@wordfence.com
tags:
  - nvd
ingestedAt: '2026-10-10T04:21:57.824Z'
---

## Overview

The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Table Field Value in all versions up to, and including, 1.4.1-RC2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
