Reflected DOM-Based Cross-Site Scripting Vulnerability in Calculated Fields Form Plugin for WordPress
CVE-2026-100179

6.1MEDIUM

What is CVE-2026-100179?

The Calculated Fields Form plugin for WordPress is susceptible to a reflected DOM-based cross-site scripting vulnerability that arises from improper input sanitization and inadequate output escaping of URL parameters consumed by the plugin’s calculated equation. If exploited, this flaw allows unauthenticated attackers to inject arbitrary web scripts that can be executed in the user's browser, given that the target site has a public form configured with a Select2-enabled dropdown, which relies on user interaction to trigger the exploit via a crafted link. This vulnerability impacts all versions of the plugin up to and including 5.5.1.3, making it imperative for site administrators to address this issue promptly.

Affected Version(s)

Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More 0 <= 5.5.1.3

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

UKO
.