Reflected DOM-Based Cross-Site Scripting Vulnerability in Calculated Fields Form Plugin for WordPress
CVE-2026-100184
4.7MEDIUM
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 1 October 2026
What is CVE-2026-100184?
The Calculated Fields Form plugin for WordPress is susceptible to a reflected DOM-based cross-site scripting flaw due to inadequate input sanitization and output escaping. This vulnerability can be exploited by unauthenticated attackers to inject arbitrary scripts, particularly when the targeted form includes a Text Area field set with a 'url.' Predefined Value and has predefinedClick disabled. Attackers can deceive users into clicking malicious links, leading to the execution of the injected scripts on vulnerable pages.
Affected Version(s)
Calculated Fields Form β AI Form Builder for WordPress β Contact, Payment, Quote, Quiz & More 0 <= 5.5.1.3