WordPress Plugin Vulnerabilities

Admin Columns for ACF Fields <= 0.3.2 - Contributor+ Stored XSS via ACF Field Value Column

Description

The plugin does not escape Advanced Custom Fields values before outputting them in the WordPress admin list-table columns, allowing users with contributor-level access or above to store a payload that executes as JavaScript in the session of higher-privileged users who view the affected post-list screen.

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Shivamani Vastrala
Submitter
Shivamani Vastrala
Verified
Yes

Timeline

Publicly Published
2026-07-17 (about 16 days ago)
Added
2026-07-10 (about 23 days ago)
Last Updated
2026-07-10 (about 23 days ago)

Other