Impact
The vulnerability allows an unauthenticated attacker to inject arbitrary JavaScript into a visitor’s browser by exploiting insufficient input sanitization and output escaping of the url.<name> parameter used in calculated field equations. This reflected DOM‑based XSS can be triggered when a user visits a crafted link that a site administrator has included in a publicly accessible form. The result is classic client‑side attack capability such as cookie theft, session hijacking, or defacement, all of which fall under CWE‑79.
Affected Systems
WordPress sites running the Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin before version 5.5.1.6 (i.e., up to and including 5.5.1.5). The issue exists only when the administrator has configured at least two URL‑based fields (url.<name>) that are combined within a concatenation equation on a publicly accessible form.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a specific form configuration and relies on a user clicking a crafted link, implying that risk is present but not ubiquitous. Nonetheless, because the impact is client‑side compromise, sites should treat the flaw with urgency. The attack vector is reflected DOM‑based XSS through URL parameter substitution, making it feasible for an attacker to deliver malicious code via a benign-looking link.
OpenCVE Enrichment