PatchSiren cyber security CVE debrief
CVE-2026-103909 codepeople CVE debrief
The Calculated Fields Form plugin for WordPress, versions up to and including 5.5.1.5, is vulnerable to Reflected DOM-Based Cross-Site Scripting. This vulnerability, caused by insufficient input sanitization and output escaping, allows unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The vulnerability exists due to the plugin's handling of the 'arbitrary (whichever names the admin bound via url.<name>)' parameter. To address this vulnerability, defenders should assess exposure, verify configurations, and prioritize remediation to prevent exploitation and the
- Vendor
- codepeople
- Product
- Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-03
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-10-03
- Advisory updated
- 2026-10-03
Who should care
Defenders responsible for WordPress installations with the Calculated Fields Form plugin should assess exposure and verify configurations to prevent exploitation. This includes reviewing the plugin's configuration, ensuring that url.<name> predefined values are not used in a concatenation equation in a publicly accessible form, and monitoring for potential exploitation attempts. Additionally, defenders should prioritize reviewing and securing the plugin's
Why it matters
The Calculated Fields Form plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting. Defenders should assess exposure, verify configurations, and prioritize remediation to prevent exploitation and potential injection of arbitrary web scripts.
- Defenders must verify if the plugin is used in their environment and if the configuration allows for exploitation.
- Successful exploitation could lead to the injection of arbitrary web scripts, potentially tricking users into performing unintended actions.
- Defenders should prioritize reviewing and securing the plugin's configuration to prevent Cross-Site Scripting attacks.
- Remediation priority is medium, as the vulnerability requires specific conditions to be met for exploitation.
Technical summary
The Calculated Fields Form plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'arbitrary (whichever names the admin bound via url.<name>)' parameter in all versions up to, and including, 5.5.1.5. This is due to insufficient input sanitization and output escaping. The vulnerability allows unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Defenders should prioritize verifying the configuration of the Calculated Fields Form plugin, particularly ensuring that url.<name> predefined values are not used in a concatenation equation in a publicly accessible form.
Defensive priority
Defenders should prioritize verifying the configuration of the Calculated Fields Form plugin, particularly ensuring that url.<name> predefined values are not used in a concatenation equation in a publicly accessible form.
Recommended defensive actions
- Verify the configuration of the Calculated Fields Form plugin to ensure that url.<name> predefined values are not used in a concatenation equation in a publicly accessible form.
- Ensure that administrators have configured fields with caution and review the plugin's documentation for secure configuration guidelines.
- Monitor for potential exploitation attempts and implement additional security measures to prevent Cross-Site Scripting attacks.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The vulnerability exists in all versions up to, and including, 5.5.1.5 of the Calculated Fields Form plugin due to insufficient input sanitization and output escaping. The 'arbitrary (whichever names the admin bound via url.<name>)' parameter is particularly susceptible to Reflected DOM-Based Cross-Site Scripting attacks. Evidence from the CVE record and NVD detail page confirms the vulnerability's existence and highlights the need for defenders to verify configurations and ensure that url.<name> predefined values are not used in a
Sources and references
Verified primary and authoritative sources
-
CVE-2026-103909 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-103909
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-103909 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-103909
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/calculated-fields-form/tags/5.5.1.5/js/fbuilder-pro-public.jquery.js
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/calculated-fields-form/tags/5.5.1.5/js/fields-public/fbuilder.fcalculated.js
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/calculated-fields-form/tags/5.5.1.5/js/modules/08_url/public/01_url.js
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.