WordPress security by component
Admin Columns for ACF Fields
Plugin description
Admin Columns for ACF Fields is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 01, 2026; an upstream CVSS base score is still pending.
Plugin slug:
admin-columns-for-acf-fieldsLatest vulnerability
CVE-2026-15262: ACF values execute stored JavaScript in administrator list tables
Admin Columns for ACF Fields through 0.3.2 outputs Advanced Custom Fields values in WordPress administration list-table columns without escaping them. A Contributor-or-higher user can store a script payload in an affected ACF value, and the JavaScript executes in a higher-privileged user's browser when that user views the corresponding post-list screen. The record does not disclose the affected field types, save path, column renderer or required payload encoding.
| Safe version |
|
||
|---|---|---|---|
| Aug 01, 2026 |
CVE-2026-15262
ACF values execute stored JavaScript in administrator list tables
Admin Columns for ACF Fields through 0.3.2 outputs Advanced Custom Fields values in WordPress administration list-table columns without escaping them. A Contributor-or-higher user can store a script payload in an affected ACF value, and the JavaScript executes in a higher-privileged user's browser when that user views the corresponding post-list screen. The record does not disclose the affected field types, save path, column renderer or required payload encoding.
|
See mitigation notes |
CVEPending
NVDPending
|