PT-2026-104503 · WordPress · Calculated Fields Form

CVE-2026-103909

·

Published

2026-10-03

·

Updated

2026-10-03

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More versions prior to 5.5.1.6
Description Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Reflected DOM-Based Cross-Site Scripting. This occurs when a site hosts a publicly accessible form where an administrator has configured at least two fields with url.<name> predefined values used together in a concatenation equation. Attackers can inject arbitrary web scripts that execute if a user is tricked into clicking a malicious link via the arbitrary (whichever names the admin bound via url.<name>) parameter.
Recommendations Update to version 5.5.1.6 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103909

Affected Products

Calculated Fields Form