Reflected DOM-Based Cross-Site Scripting in Calculated Fields Form Plugin for WordPress
CVE-2026-103909

6.1MEDIUM

What is CVE-2026-103909?

The Calculated Fields Form plugin for WordPress is susceptible to a Reflected DOM-Based Cross-Site Scripting vulnerability. This issue arises from the insufficient sanitization of user inputs via the 'arbitrary' parameter, allowing hostile actors to inject malicious scripts. If successful, attackers can exploit this vulnerability by deceiving users into clicking on crafted links that trigger the execution of these scripts. The vulnerability specifically affects instances where the site administrator has configured multiple fields using predefined values, posing a significant risk to sites hosting accessible forms.

Affected Version(s)

Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More 0 <= 5.5.1.5

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

UKO
.