CVE · Medium

CVE-2025-12067 — Table Field Add-on for ACF and SCF [advanced-custom-fields-table-field] < 1.3.31

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-12067 Table Field Add-on for ACF and SCF [advanced-custom-fields-table-field] < 1.3.31 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 1.3.31 1.3.31 2026-01-05

CVE-2025-12067

The Table Field Add-on plugin for WordPress has a security flaw affecting versions up to 1.3.30. The issue arises from inadequate handling of input data, allowing malicious code to be embedded within table cell content. As a result, attackers with Author-level access or higher can inject executable scripts that will run when users visit the compromised page.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.