Reflected DOM-Based Cross-Site Scripting Vulnerability in Calculated Fields Form Plugin for WordPress
CVE-2026-100184

4.7MEDIUM

What is CVE-2026-100184?

The Calculated Fields Form plugin for WordPress is susceptible to a reflected DOM-based cross-site scripting flaw due to inadequate input sanitization and output escaping. This vulnerability can be exploited by unauthenticated attackers to inject arbitrary scripts, particularly when the targeted form includes a Text Area field set with a 'url.' Predefined Value and has predefinedClick disabled. Attackers can deceive users into clicking malicious links, leading to the execution of the injected scripts on vulnerable pages.

Affected Version(s)

Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More 0 <= 5.5.1.3

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

UKO
.