CVE-2026-103909 Overview
CVE-2026-103909 is a Reflected DOM-Based Cross-Site Scripting (XSS) vulnerability in the Calculated Fields Form – AI Form Builder plugin for WordPress. The flaw affects all versions up to and including 5.5.1.5. It stems from insufficient input sanitization and output escaping on an administrator-defined URL parameter bound through url.<name> predefined values. Unauthenticated attackers can inject arbitrary JavaScript that executes in a victim's browser when the victim clicks a crafted link. The vulnerability is tracked under CWE-79.
Critical Impact
Successful exploitation enables script execution in the victim's browser session, enabling session theft, credential harvesting, or redirection, but requires user interaction and a specific plugin configuration.
Affected Products
- Calculated Fields Form – AI Form Builder for WordPress plugin
- All plugin versions through 5.5.1.5
- WordPress sites hosting publicly accessible forms with two or more url.<name> predefined fields used in a concatenation equation
Discovery Timeline
- 2026-10-03 - CVE-2026-103909 published to NVD
- 2026-10-06 - Last updated in NVD database
Technical Details for CVE-2026-103909
Vulnerability Analysis
The Calculated Fields Form plugin lets administrators bind form field values to URL query parameters using url.<name> syntax. When a form is rendered, the plugin reads the specified query string parameter from the current URL and injects it into field values on the client side. The plugin's JavaScript does not sanitize or escape these values before passing them into DOM operations that execute within calculation equations.
Because the reflection and execution occur entirely in the browser, this is a DOM-based XSS. The attack is unauthenticated — any visitor who follows a crafted link to a vulnerable form page triggers the payload. The attacker needs no plugin privileges, but the targeted site must host a form that an administrator has configured with at least two url.<name> predefined fields referenced together in a concatenation equation.
Root Cause
The root cause is missing input sanitization and output escaping in the plugin's client-side URL parameter handling. The vulnerable code paths are visible in the plugin source at fbuilder-pro-public.jquery.js L1288, L167, fbuilder.fcalculated.js L389, L416, and 01_url.js L140. Attacker-controlled URL input flows into DOM write operations and expression evaluation without encoding.
Attack Vector
The attack vector is network-based with required user interaction. An attacker crafts a URL to a vulnerable WordPress page containing the calculated form, embedding malicious JavaScript inside the url.<name> query parameters that the admin bound. When a victim clicks the link, the plugin's script reads the parameters and executes the payload in the victim's browser, inheriting the origin of the WordPress site. See the Wordfence Vulnerability Report for additional technical context.
Detection Methods for CVE-2026-103909
Indicators of Compromise
- Inbound HTTP requests to pages hosting the Calculated Fields Form with suspicious query string parameters containing HTML tags, javascript: schemes, or event handlers such as onerror= and onload=
- Referer logs showing visitors arriving at form pages from external links with encoded script payloads in the query string
- Browser Content Security Policy (CSP) violation reports originating from pages that embed the vulnerable plugin
- Unexpected outbound requests from client browsers to attacker-controlled domains after visiting a form page
Detection Strategies
- Inventory WordPress sites running the Calculated Fields Form plugin at version 5.5.1.5 or earlier
- Audit form configurations for predefined url.<name> field bindings that participate in concatenation equations
- Deploy web application firewall (WAF) rules that flag query string parameters containing script tags, JavaScript URI schemes, or HTML event handler attributes on URLs targeting form pages
- Correlate web access logs with endpoint telemetry to identify users who followed suspicious URLs to WordPress form pages
Monitoring Recommendations
- Enable CSP reporting on WordPress sites and forward violation reports to a centralized log platform
- Monitor the WordPress plugin repository and vendor changelog for updates beyond version 5.5.1.5
- Track user clicks on externally sourced links that resolve to WordPress form endpoints in email security and web proxy logs
How to Mitigate CVE-2026-103909
Immediate Actions Required
- Update the Calculated Fields Form plugin to a version newer than 5.5.1.5 once the vendor publishes a patched release
- Review all forms using url.<name> predefined values and remove or reconfigure fields that are not strictly required
- Deploy WAF rules to block query strings containing script injection payloads targeting pages that host the vulnerable plugin
- Educate administrators and end users to avoid clicking unsolicited links to form pages
Patch Information
The vendor commit tracking the fix is referenced in the WordPress Changeset Overview. Site administrators should apply the latest plugin version from the WordPress plugin repository and verify form behavior after upgrade. Consult the Wordfence Vulnerability Report for fixed-version details.
Workarounds
- Remove or disable public-facing forms that bind two or more fields to url.<name> predefined values used in concatenation equations
- Enforce a strict Content Security Policy that disallows inline script execution on pages hosting the plugin
- Temporarily deactivate the Calculated Fields Form plugin on sites where immediate patching is not feasible
# Example CSP header to restrict inline script execution on WordPress pages
Content-Security-Policy: default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'self'
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.