WordPress Plugin Vulnerabilities

Admin Columns for ACF Fields <= 0.3.2 - Contributor+ Stored XSS via ACF Field Value Column

Description

The plugin does not escape Advanced Custom Fields values before outputting them in the WordPress admin list-table columns, allowing users with contributor-level access or above to store a payload that executes as JavaScript in the session of higher-privileged users who view the affected post-list screen.

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Shivamani Vastrala
Submitter
Shivamani Vastrala
Verified
Yes

Timeline

Publicly Published
2026-07-17 (about 1 month ago)
Added
2026-07-10 (about 2 months ago)
Last Updated
2026-07-10 (about 2 months ago)

Other