CVE-2026-100184
Received Received - Intake

Reflected DOM-Based XSS in Calculated Fields Form WordPress Plugin

Vulnerability report for CVE-2026-100184, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Wordfence

Description

The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'x (attacker-chosen name matching the form's url.<name> predefined value)' parameter in all versions up to, and including, 5.5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that the targeted form has a Text Area field configured with a 'url.<name>' Predefined Value and predefinedClick disabled, which is a documented and commonly used plugin feature.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
calculated_fields_form calculated_fields_form to 5.5.1.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Reflected DOM-Based Cross-Site Scripting (XSS) issue in the Calculated Fields Form – AI Form Builder for WordPress plugin. It allows unauthenticated attackers to inject malicious scripts via a parameter named 'x' in the URL, which matches a form's predefined value like 'url.<name>'. The attack requires a user to click a crafted link and works only if the targeted form has a Text Area field with a 'url.<name>' Predefined Value and predefinedClick disabled.

The flaw exists due to insufficient input sanitization and output escaping in the plugin, enabling attackers to execute arbitrary web scripts in affected pages.

Detection Guidance

This vulnerability is specific to the Calculated Fields Form WordPress plugin. Detection requires checking if the plugin is installed and verifying its version. Use WordPress admin panel or commands like 'wp plugin list' in WP-CLI to check the plugin version. If version is up to 5.5.1.3, the site is vulnerable.

Impact Analysis

This vulnerability could allow attackers to steal sensitive user data, such as cookies or session tokens, by tricking users into clicking a malicious link. It may also enable attackers to perform actions on behalf of users, modify page content, or redirect users to phishing sites.

The impact depends on user privileges and the data processed by the affected WordPress forms. Unauthenticated attackers can exploit this without needing user credentials.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR and HIPAA requirements for data protection and confidentiality. Organizations using the affected plugin may face compliance breaches if user data is compromised through XSS attacks.

Failure to address this vulnerability may result in regulatory fines, reputational damage, and loss of trust due to inadequate security measures protecting sensitive user information.

Mitigation Strategies

Immediately update the Calculated Fields Form plugin to the latest version available. If an update is not available, consider disabling or removing the plugin until a patch is released. Review all forms for Text Area fields with 'url.<name>' Predefined Values and ensure predefinedClick is enabled.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100184. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart