CVE-2026-100184: Calculated Fields Form <= 5.5.1.3 - Reflected DOM-Based Cross-Site Scripting via 'x' URL Query Parameter via Text Area Predefined Value

Published Oct 1, 2026
·
Updated

The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'x (attacker-chosen name matching the form's url.<name> predefined value)' parameter in all versions up to, and including, 5.5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that the targeted form has a Text Area field configured with a 'url.<name>' Predefined Value and predefinedClick disabled, which is a documented and commonly used plugin feature.

Affected Software

1 affected component
CodePeople Calculated Fields Form<=5.5.1.3

Event History

Oct 1, 2026
CVE Published
via MITRE·08:28 AM
Data Sourced
via MITRE·08:28 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which sites are exposed to exploitation?

Sites using Calculated Fields Form version 5.5.1.3 or earlier are exposed only where a targeted form includes a Text Area field configured with a url.<name> Predefined Value and has predefinedClick disabled. This configuration is documented and commonly used.

2

What does an attacker need to exploit this issue?

No authentication is required, but the attacker must know or choose the query-parameter name corresponding to the form's url.<name> predefined value. They must also persuade a victim to perform an action such as clicking a crafted link.

3

Is a default installation affected?

The issue depends on a specific form-field configuration rather than being described as affecting every form by default. Forms without the relevant Text Area url.<name> Predefined Value configuration and predefinedClick disabled are not identified as exploitable by the provided information.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203