CVE-2026-100179: Calculated Fields Form <= 5.5.1.3 - Reflected DOM-Based Cross-Site Scripting via 'x' URL Parameter via setChoices()
The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'x (any URL parameter consumed by the form's calculated equation)' parameter in all versions up to, and including, 5.5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires the target site to have a public form configured with a Select2-enabled dropdown whose choices are populated via a calculated equation that pipes a URL parameter through GETURLPARAMETER() into setChoices({texts:[...]}); given that configuration, exploitation requires only a single crafted link.
Affected Software
Event History
Frequently Asked Questions
Which sites are exposed to exploitation?
A site is exposed only if it has a public form with a Select2-enabled dropdown whose choices are populated by a calculated equation that passes a URL parameter through GETURLPARAMETER() into setChoices({texts:[...]}). Sites using the plugin without that specific form configuration are not described as exploitable by this issue.
What does an attacker need to exploit this vulnerability?
The attacker does not need authentication, but must send a crafted link to a user and convince that user to click it or otherwise load it. The vulnerable form configuration must be present on the page reached by the link.
How can administrators identify potentially affected forms?
Review public forms for Select2-enabled dropdowns and inspect their calculated equations for use of GETURLPARAMETER() to supply values to setChoices({texts:[...]}). Forms matching that data flow are the configurations identified as vulnerable.
What can be done while a patch is unavailable?
Remove or disable the affected public form configuration, or stop passing URL-parameter values through GETURLPARAMETER() into setChoices({texts:[...]}). This prevents the described injection path.