PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-103909 codepeople CVE debrief

The Calculated Fields Form plugin for WordPress, versions up to and including 5.5.1.5, is vulnerable to Reflected DOM-Based Cross-Site Scripting. This vulnerability, caused by insufficient input sanitization and output escaping, allows unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The vulnerability exists due to the plugin's handling of the 'arbitrary (whichever names the admin bound via url.<name>)' parameter. To address this vulnerability, defenders should assess exposure, verify configurations, and prioritize remediation to prevent exploitation and the

Vendor
codepeople
Product
Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-03
Original CVE updated
2026-10-03
Advisory published
2026-10-03
Advisory updated
2026-10-03

Who should care

Defenders responsible for WordPress installations with the Calculated Fields Form plugin should assess exposure and verify configurations to prevent exploitation. This includes reviewing the plugin's configuration, ensuring that url.<name> predefined values are not used in a concatenation equation in a publicly accessible form, and monitoring for potential exploitation attempts. Additionally, defenders should prioritize reviewing and securing the plugin's

Why it matters

The Calculated Fields Form plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting. Defenders should assess exposure, verify configurations, and prioritize remediation to prevent exploitation and potential injection of arbitrary web scripts.

  • Defenders must verify if the plugin is used in their environment and if the configuration allows for exploitation.
  • Successful exploitation could lead to the injection of arbitrary web scripts, potentially tricking users into performing unintended actions.
  • Defenders should prioritize reviewing and securing the plugin's configuration to prevent Cross-Site Scripting attacks.
  • Remediation priority is medium, as the vulnerability requires specific conditions to be met for exploitation.

Technical summary

The Calculated Fields Form plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'arbitrary (whichever names the admin bound via url.<name>)' parameter in all versions up to, and including, 5.5.1.5. This is due to insufficient input sanitization and output escaping. The vulnerability allows unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Defenders should prioritize verifying the configuration of the Calculated Fields Form plugin, particularly ensuring that url.<name> predefined values are not used in a concatenation equation in a publicly accessible form.

Defensive priority

Defenders should prioritize verifying the configuration of the Calculated Fields Form plugin, particularly ensuring that url.<name> predefined values are not used in a concatenation equation in a publicly accessible form.

Recommended defensive actions

  • Verify the configuration of the Calculated Fields Form plugin to ensure that url.<name> predefined values are not used in a concatenation equation in a publicly accessible form.
  • Ensure that administrators have configured fields with caution and review the plugin's documentation for secure configuration guidelines.
  • Monitor for potential exploitation attempts and implement additional security measures to prevent Cross-Site Scripting attacks.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The vulnerability exists in all versions up to, and including, 5.5.1.5 of the Calculated Fields Form plugin due to insufficient input sanitization and output escaping. The 'arbitrary (whichever names the admin bound via url.<name>)' parameter is particularly susceptible to Reflected DOM-Based Cross-Site Scripting attacks. Evidence from the CVE record and NVD detail page confirms the vulnerability's existence and highlights the need for defenders to verify configurations and ensure that url.<name> predefined values are not used in a

Sources and references

Verified primary and authoritative sources

  • CVE-2026-103909 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-103909

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-103909 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-103909

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/calculated-fields-form/tags/5.5.1.5/js/fbuilder-pro-public.jquery.js

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/calculated-fields-form/tags/5.5.1.5/js/fields-public/fbuilder.fcalculated.js

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/calculated-fields-form/tags/5.5.1.5/js/modules/08_url/public/01_url.js

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.