Reflected DOM-Based Cross-Site Scripting in Calculated Fields Form Plugin for WordPress
CVE-2026-103909
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-103909?
The Calculated Fields Form plugin for WordPress is susceptible to a Reflected DOM-Based Cross-Site Scripting vulnerability. This issue arises from the insufficient sanitization of user inputs via the 'arbitrary' parameter, allowing hostile actors to inject malicious scripts. If successful, attackers can exploit this vulnerability by deceiving users into clicking on crafted links that trigger the execution of these scripts. The vulnerability specifically affects instances where the site administrator has configured multiple fields using predefined values, posing a significant risk to sites hosting accessible forms.
Affected Version(s)
Calculated Fields Form β AI Form Builder for WordPress β Contact, Payment, Quote, Quiz & More 0 <= 5.5.1.5