Reflected DOM-Based Cross-Site Scripting Vulnerability in Calculated Fields Form Plugin for WordPress
CVE-2026-100179
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 1 October 2026
What is CVE-2026-100179?
The Calculated Fields Form plugin for WordPress is susceptible to a reflected DOM-based cross-site scripting vulnerability that arises from improper input sanitization and inadequate output escaping of URL parameters consumed by the pluginβs calculated equation. If exploited, this flaw allows unauthenticated attackers to inject arbitrary web scripts that can be executed in the user's browser, given that the target site has a public form configured with a Select2-enabled dropdown, which relies on user interaction to trigger the exploit via a crafted link. This vulnerability impacts all versions of the plugin up to and including 5.5.1.3, making it imperative for site administrators to address this issue promptly.
Affected Version(s)
Calculated Fields Form β AI Form Builder for WordPress β Contact, Payment, Quote, Quiz & More 0 <= 5.5.1.3