Description
The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'x (attacker-chosen name matching the form's url.<name> predefined value)' parameter in all versions up to, and including, 5.5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that the targeted form has a Text Area field configured with a 'url.<name>' Predefined Value and predefinedClick disabled, which is a documented and commonly used plugin feature.
Published: 2026-10-01
Score: 4.7 Medium
EPSS: n/a
KEV: No
Impact: Reflected DOM‑based Cross‑Site Scripting
Action: Assess Impact
AI Analysis

Impact

The vulnerability is a reflected DOM‑based cross‑site scripting flaw that is triggered through the 'x' URL query parameter when a plugin's Text Area field is configured with a 'url.<name>' predefined value and the predefinedClick option is disabled. Attacks allow an unauthenticated attacker to inject arbitrary JavaScript that will run in the victim browser when the victim follows a specially crafted link. The flaw arises from insufficient input sanitization and output escaping within the plugin's JavaScript rendering logic.

Affected Systems

The vulnerability exists in all releases of the Calculated Fields Form – AI Form Builder for WordPress plugin up to and including version 5.5.1.3. Any WordPress installation using these versions with a form that contains a Text Area field configured with a 'url.<name>' predefined value and with predefinedClick disabled is potentially vulnerable.

Risk and Exploitability

The CVSS base score of 4.7 indicates a moderate risk level. The EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. Because the attack requires social‑engineering tactics—tricking a user to click a malicious link—the likelihood of exploitation is moderate but not negligible. If the attacker can craft a URL that targets a vulnerable form, the injected script can execute in the context of the victim’s browser session, potentially allowing DOM manipulation, cookie theft, or redirection to malicious sites.

Generated by OpenCVE AI on October 1, 2026 at 10:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Calculated Fields Form plugin to the latest version (≥5.5.1.4) which removes or sanitizes the 'x' parameter handling.
  • If an upgrade is not possible, modify affected forms by either removing the Text Area field, removing the 'url.<name>' predefined value, or enabling the predefinedClick option to prevent the parameter from being reflected.
  • Regularly review plugin configuration and usage of the 'url.<name>' feature, and apply proper input validation and escaping in custom scripts to mitigate similar vulnerabilities.
  • Consider implementing a Web Application Firewall rule to filter malicious JavaScript patterns in the 'x' query parameter.

Generated by OpenCVE AI on October 1, 2026 at 10:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Codepeople
Codepeople calculated Fields Form
Wordpress-extensions
Wordpress-extensions calculated Fields Form
Vendors & Products Codepeople
Codepeople calculated Fields Form
Wordpress-extensions
Wordpress-extensions calculated Fields Form

Thu, 01 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'x (attacker-chosen name matching the form's url.<name> predefined value)' parameter in all versions up to, and including, 5.5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that the targeted form has a Text Area field configured with a 'url.<name>' Predefined Value and predefinedClick disabled, which is a documented and commonly used plugin feature.
Title Calculated Fields Form <= 5.5.1.3 - Reflected DOM-Based Cross-Site Scripting via 'x' URL Query Parameter via Text Area Predefined Value
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Codepeople Calculated Fields Form
Wordpress-extensions Calculated Fields Form
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-01T08:28:44.400Z

Reserved: 2026-09-25T13:40:20.684Z

Link: CVE-2026-100184

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T09:17:07.423

Modified: 2026-10-01T12:40:28.083

Link: CVE-2026-100184

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:35:54Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')