Impact
A reflected DOM‑based XSS flaw exists in all versions of the AI Form Builder for WordPress plugin up to 5.5.1.3, allowing an unauthenticated attacker to inject arbitrary JavaScript into pages that display public forms. The vulnerability stems from the plugin’s insufficient sanitization and output escaping of the URL parameter used by the getURLParameter() function within a setChoices() call, which is a classic reflected XSS weakness (CWE‑79). Successful exploitation enables attackers to hijack user sessions, steal data, deface sites, or trigger other malicious actions when a victim clicks a crafted link.
Affected Systems
WordPress sites that have installed the Calculated Fields Form – AI Form Builder for WordPress plugin (vendor codepeople) with any version up to and including 5.5.1.3 deployed. The flaw is active only when a public form uses a Select2‑enabled dropdown populated via a calculated equation that passes a URL parameter into setChoices()’s texts array.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate risk, and the EPSS score is not provided, suggesting no publicly known widespread exploitation at the time of reporting. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only a single crafted link directed at a public form that meets the described configuration, and an attacker does not need advanced privileges. The attack vector is remote, leveraging a web request that contains the malicious query string and causes the victim’s browser to execute injected code. Because the flaw is client‑side, the impact is limited to the victim’s session, but it can lead to credential theft, defacement, or further attacks initiated from the compromised user context.
OpenCVE Enrichment