← WordPress Vulnerabilities
WordPress security by component

Admin Columns for ACF Fields

Admin Columns for ACF Fields is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 01, 2026; an upstream CVSS base score is still pending.

Plugin slug: admin-columns-for-acf-fields

CVE-2026-15262: ACF values execute stored JavaScript in administrator list tables

Admin Columns for ACF Fields through 0.3.2 outputs Advanced Custom Fields values in WordPress administration list-table columns without escaping them. A Contributor-or-higher user can store a script payload in an affected ACF value, and the JavaScript executes in a higher-privileged user's browser when that user views the corresponding post-list screen. The record does not disclose the affected field types, save path, column renderer or required payload encoding.

PublishedAug 01, 2026
Safe version guidanceSee mitigation notes
Safe version
Aug 01, 2026 CVE-2026-15262
ACF values execute stored JavaScript in administrator list tables
Admin Columns for ACF Fields through 0.3.2 outputs Advanced Custom Fields values in WordPress administration list-table columns without escaping them. A Contributor-or-higher user can store a script payload in an affected ACF value, and the JavaScript executes in a higher-privileged user's browser when that user views the corresponding post-list screen. The record does not disclose the affected field types, save path, column renderer or required payload encoding.
See mitigation notes
CVEPending
NVDPending