Description
The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'arbitrary (whichever names the admin bound via url.<name>)' parameter in all versions up to, and including, 5.5.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires the targeted site to host a publicly accessible form in which an administrator has configured at least two fields with url.&lt;name&gt; predefined values that are used together in a concatenation equation — a plausible but not universal configuration.
Published: 2026-10-03
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Reflected DOM-based Cross‑Site Scripting (XSS)
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an unauthenticated attacker to inject arbitrary JavaScript into a visitor’s browser by exploiting insufficient input sanitization and output escaping of the url.<name> parameter used in calculated field equations. This reflected DOM‑based XSS can be triggered when a user visits a crafted link that a site administrator has included in a publicly accessible form. The result is classic client‑side attack capability such as cookie theft, session hijacking, or defacement, all of which fall under CWE‑79.

Affected Systems

WordPress sites running the Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin before version 5.5.1.6 (i.e., up to and including 5.5.1.5). The issue exists only when the administrator has configured at least two URL‑based fields (url.<name>) that are combined within a concatenation equation on a publicly accessible form.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a specific form configuration and relies on a user clicking a crafted link, implying that risk is present but not ubiquitous. Nonetheless, because the impact is client‑side compromise, sites should treat the flaw with urgency. The attack vector is reflected DOM‑based XSS through URL parameter substitution, making it feasible for an attacker to deliver malicious code via a benign-looking link.

Generated by OpenCVE AI on October 3, 2026 at 06:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Calculated Fields Form plugin to the latest release that removes the vulnerability.
  • If an immediate update is not possible, remove all url.<name> fields from form equations or disable URL field usage entirely to prevent the XSS vector.
  • Implement server‑side validation that ensures any user‑supplied values in calculated field equations are strictly whitelisted and properly escaped before rendering.

Generated by OpenCVE AI on October 3, 2026 at 06:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Description The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'arbitrary (whichever names the admin bound via url.<name>)' parameter in all versions up to, and including, 5.5.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires the targeted site to host a publicly accessible form in which an administrator has configured at least two fields with url.&lt;name&gt; predefined values that are used together in a concatenation equation — a plausible but not universal configuration.
Title Calculated Fields Form <= 5.5.1.5 - Reflected DOM-Based Cross-Site Scripting via URL Parameter Substitution in Calculated Field Equation
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:43.422Z

Reserved: 2026-10-01T14:16:34.128Z

Link: CVE-2026-103909

cve-icon Vulnrichment

Updated: 2026-10-03T15:39:05.912Z

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:41.413

Modified: 2026-10-03T16:16:34.220

Link: CVE-2026-103909

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T06:30:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')