Impact
The vulnerability is a reflected DOM‑based cross‑site scripting flaw that is triggered through the 'x' URL query parameter when a plugin's Text Area field is configured with a 'url.<name>' predefined value and the predefinedClick option is disabled. Attacks allow an unauthenticated attacker to inject arbitrary JavaScript that will run in the victim browser when the victim follows a specially crafted link. The flaw arises from insufficient input sanitization and output escaping within the plugin's JavaScript rendering logic.
Affected Systems
The vulnerability exists in all releases of the Calculated Fields Form – AI Form Builder for WordPress plugin up to and including version 5.5.1.3. Any WordPress installation using these versions with a form that contains a Text Area field configured with a 'url.<name>' predefined value and with predefinedClick disabled is potentially vulnerable.
Risk and Exploitability
The CVSS base score of 4.7 indicates a moderate risk level. The EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. Because the attack requires social‑engineering tactics—tricking a user to click a malicious link—the likelihood of exploitation is moderate but not negligible. If the attacker can craft a URL that targets a vulnerable form, the injected script can execute in the context of the victim’s browser session, potentially allowing DOM manipulation, cookie theft, or redirection to malicious sites.
OpenCVE Enrichment