Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100184— Calculated Fields Form <= 5.5.1.3 - Reflected DOM-Based Cross-Site Scripting via 'x' URL Query Parameter via Text Area Predefined Value

Quick assessment

Affected
codepeople Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 插件“Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More”(计算字段表单 – 用于 WordPress 的 AI 表单构建器 – 支持联系、支付、报价、测验等)在包括 5.5.1.3 在内的所有版本中,存在通过 (攻击者选定的名称,需匹配表单的 预定义值)参数引发的反射型 DOM 跨站脚本(Reflected DOM-Based XSS)漏洞。该漏洞源于输入净化

CVSS 4.7 · Medium

Possible ATT&CK Techniques 1 AI

T1059.007 · JavaScript
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100184

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Calculated Fields Form <= 5.5.1.3 - Reflected DOM-Based Cross-Site Scripting via 'x' URL Query Parameter via Text Area Predefined Value
Source: CVE Program / CVE List V5
Vulnerability Description
The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'x (attacker-chosen name matching the form's url.<name> predefined value)' parameter in all versions up to, and including, 5.5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that the targeted form has a Text Area field configured with a 'url.<name>' Predefined Value and predefinedClick disabled, which is a documented and commonly used plugin feature.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

II. Public POCs for CVE-2026-100184

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100184

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-100184 (1)

Vendor Advisories for CVE-2026-100184 (1)

Other References for CVE-2026-100184 (4)

Same Patch Batch · codepeople · 2026-10-01 · 3 CVEs total

CVE-2026-96573 7.2 HIGH Appointment Hour Booking <= 1.5.97 - Unauthenticated Stored DOM-Based Cross-Site Scripting
CVE-2026-100179 6.1 MEDIUM Calculated Fields Form <= 5.5.1.3 - Reflected DOM-Based Cross-Site Scripting via 'x' URL P

IV. Related Vulnerabilities

V. Comments for CVE-2026-100184

No comments yet


Leave a comment