๐Ÿ” CVE Alert

CVE-2026-15262

UNKNOWN 0.0

Admin Columns for ACF Fields <= 0.3.2 - Contributor+ Stored XSS via ACF Field Value Column

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fields values before outputting them in the WordPress admin list-table columns, allowing users with contributor-level access or above to store a payload that executes as JavaScript in the session of higher-privileged users who view the affected post-list screen.

Vendor unknown
Product admin columns for acf fields
Published Aug 1, 2026
Stay Ahead of the Next One

Get instant alerts for unknown admin columns for acf fields

Be the first to know when new unknown vulnerabilities affecting unknown admin columns for acf fields are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Admin Columns for ACF Fields
0 โ‰ค 0.3.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/dea1f3a9-2681-47a6-9e36-9d6ea799decb/

Credits

Shivamani Vastrala WPScan