Description
The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'x (any URL parameter consumed by the form's calculated equation)' parameter in all versions up to, and including, 5.5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires the target site to have a public form configured with a Select2-enabled dropdown whose choices are populated via a calculated equation that pipes a URL parameter through GETURLPARAMETER() into setChoices({texts:[...]}); given that configuration, exploitation requires only a single crafted link.
Published: 2026-10-01
Score: 6.1 Medium
EPSS: n/a
KEV: No
Impact: DOM‑based Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

A reflected DOM‑based XSS flaw exists in all versions of the AI Form Builder for WordPress plugin up to 5.5.1.3, allowing an unauthenticated attacker to inject arbitrary JavaScript into pages that display public forms. The vulnerability stems from the plugin’s insufficient sanitization and output escaping of the URL parameter used by the getURLParameter() function within a setChoices() call, which is a classic reflected XSS weakness (CWE‑79). Successful exploitation enables attackers to hijack user sessions, steal data, deface sites, or trigger other malicious actions when a victim clicks a crafted link.

Affected Systems

WordPress sites that have installed the Calculated Fields Form – AI Form Builder for WordPress plugin (vendor codepeople) with any version up to and including 5.5.1.3 deployed. The flaw is active only when a public form uses a Select2‑enabled dropdown populated via a calculated equation that passes a URL parameter into setChoices()’s texts array.

Risk and Exploitability

The CVSS score of 6.1 indicates a moderate risk, and the EPSS score is not provided, suggesting no publicly known widespread exploitation at the time of reporting. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only a single crafted link directed at a public form that meets the described configuration, and an attacker does not need advanced privileges. The attack vector is remote, leveraging a web request that contains the malicious query string and causes the victim’s browser to execute injected code. Because the flaw is client‑side, the impact is limited to the victim’s session, but it can lead to credential theft, defacement, or further attacks initiated from the compromised user context.

Generated by OpenCVE AI on October 1, 2026 at 10:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Calculated Fields Form plugin to the latest version that addresses the XSS flaw
  • Reconfigure or remove any public forms that currently use a Select2 dropdown populated via getURLParameter() into setChoices()
  • Apply a content‑security‑policy that restricts inline script execution and sources to trusted origins

Generated by OpenCVE AI on October 1, 2026 at 10:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'x (any URL parameter consumed by the form's calculated equation)' parameter in all versions up to, and including, 5.5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires the target site to have a public form configured with a Select2-enabled dropdown whose choices are populated via a calculated equation that pipes a URL parameter through GETURLPARAMETER() into setChoices({texts:[...]}); given that configuration, exploitation requires only a single crafted link.
Title Calculated Fields Form <= 5.5.1.3 - Reflected DOM-Based Cross-Site Scripting via 'x' URL Parameter via setChoices()
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-01T14:07:25.580Z

Reserved: 2026-09-25T13:35:52.516Z

Link: CVE-2026-100179

cve-icon Vulnrichment

Updated: 2026-10-01T14:07:03.607Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T09:17:06.227

Modified: 2026-10-01T15:17:17.540

Link: CVE-2026-100179

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T10:45:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')