CVE-2026-103909: Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More
- Severity
- 6.1 (MEDIUM)
- Vendor
- CODEPEOPLE
- Affected versions
- 0 through 5.5.1.5
- Patch status
- Unknown
- Published
- 2026-10-03T06:16:41.413
- Modified
- 2026-10-03T16:16:34.220
Why it matters
This matters because the affected product may be exposed on public websites. A vulnerable plugin can create a direct path to site compromise, malicious code deployment, or data theft.
Recommended admin actions
- Review during normal vulnerability triage unless the affected system is internet-facing or business-critical.
- Check whether the affected WordPress plugin or theme is installed.
- Update, disable, or remove the affected component if present.
- Treat internet-facing systems as higher priority.
- Review logs for suspicious activity related to the affected application or component.
Technical summary
The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'arbitrary (whichever names the admin bound via url.)' parameter in all versions up to, and including, 5.5.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires the targeted site to host a publicly accessible form in which an administrator has configured at least two fields with url.<name> predefined values that are used together in a concatenation equation — a plausible but not universal configuration.
View the official NVD record for CVE-2026-103909
CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.
VULNERABILITY PULSE
| AFFECTED PRODUCT | ACTION | ||
|---|---|---|---|
| CVE-2026-105105 |
AIT-Core
Reporter: 309F9EA4-E3E9-4C6C-B79D-E8EB01244F2C
|
9.8
CRITICAL
|
VIEW RECORD |
| CVE-2026-105080 |
Product identification pending PATCH
Reporter: CVE
|
9.4
CRITICAL
|
VIEW RECORD |
| CVE-2026-71885 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
9.2
CRITICAL
|
VIEW RECORD |
| CVE-2026-87115 |
VikAppointments Services Booking Calendar
Reporter: SECURITY
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-92084 |
Beaver Builder Page Builder – Drag and Drop Website Builder
Reporter: SECURITY
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-92536 |
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
Reporter: SECURITY
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-97644 |
Groundhogg — CRM, Newsletters, and Marketing Automation
Reporter: SECURITY
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-88783 |
Kubio AI Page Builder PATCH
Reporter: CONTACT
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-18443 |
Smart Manager – WooCommerce Bulk Edit: Products, Orders, Users & More (Spreadsheet)
Reporter: SECURITY
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-105115 |
OpenAM PATCH
Reporter: DISCLOSURE
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-96451 |
Ultimate Member PATCH
Reporter: AUDIT
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-104433 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-71888 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-71889 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-71890 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-89236 |
SaveTo Wishlist Lite PATCH
Reporter: CONTACT
|
8.6
HIGH
|
VIEW RECORD |
| CVE-2026-104476 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-91078 |
TillKit PATCH
Reporter: CONTACT
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-71883 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-71886 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-71887 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-85515 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-103065 |
Kirki PATCH
Reporter: AUDIT
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-101923 |
Photo Reviews for WooCommerce
Reporter: SECURITY
|
8.1
HIGH
|
VIEW RECORD |
| CVE-2026-94505 |
Nelio Content – Editorial Calendar & Social Media Auto-Posting
Reporter: SECURITY
|
8.1
HIGH
|
VIEW RECORD |
| CVE-2026-105119 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
7.6
HIGH
|
VIEW RECORD |
| CVE-2026-93428 |
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-101159 |
WP Ultimate Review PATCH
Reporter: CONTACT
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-101160 |
WP Ultimate Review PATCH
Reporter: CONTACT
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-101161 |
WP Ultimate Review PATCH
Reporter: CONTACT
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-103514 |
WP 2FA PATCH
Reporter: CONTACT
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-103913 |
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-97337 |
Simple Membership
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-75028 |
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-96267 |
WP Visitor Statistics (Real Time Traffic)
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-96270 |
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-92977 |
Real Cookie Banner: GDPR & ePrivacy Cookie Consent
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-101928 |
Magic Tooltips For Contact Form 7
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-87091 |
Welcart e-Commerce
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-93430 |
GD Rating System
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-96564 |
SEOPress – AI SEO Plugin & On-site SEO
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-96575 |
Transliterator – Multilingual and Multi-script Text Conversion
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-96650 |
Strong Testimonials
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-97341 |
Visitor Traffic Real Time Statistics
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-93889 |
Mail logging & Catcher
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-97660 |
WPC Product Options for WooCommerce
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-104478 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-71891 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-105113 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-103342 |
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) PATCH
Reporter: AUDIT
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-105030 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-71892 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-105120 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-105121 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-103293 |
MPG PATCH
Reporter: CONTACT
|
6.8
MEDIUM
|
VIEW RECORD |
| CVE-2026-85568 |
Unlimited Elements for Elementor PATCH
Reporter: CONTACT
|
6.8
MEDIUM
|
VIEW RECORD |
| CVE-2026-88782 |
Kubio AI Page Builder PATCH
Reporter: CONTACT
|
6.8
MEDIUM
|
VIEW RECORD |
| CVE-2026-94238 |
Loco Translate PATCH
Reporter: CONTACT
|
6.8
MEDIUM
|
VIEW RECORD |
| CVE-2026-94239 |
Loco Translate PATCH
Reporter: CONTACT
|
6.8
MEDIUM
|
VIEW RECORD |
| CVE-2026-85015 |
Unlimited Elements for Elementor PATCH
Reporter: CONTACT
|
6.6
MEDIUM
|
VIEW RECORD |
| CVE-2026-94539 |
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent
Reporter: SECURITY
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-95865 |
Beaver Builder Page Builder – Drag and Drop Website Builder
Reporter: SECURITY
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-100152 |
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)
Reporter: SECURITY
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-100157 |
WP Ultimate Review
Reporter: SECURITY
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-94378 |
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-92727 |
EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2025-12828 |
Ultra Addons Lite for Elementor
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-100148 |
Rich Showcase for Google Reviews
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-101162 |
WP Ultimate Review PATCH
Reporter: CONTACT
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-97344 |
Wp Social Login and Register Social Counter
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-15795 |
Responsive Starter Templates – Elementor Templates & Starter Sites
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-92767 |
Twenty20 Image Before-After
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-92923 |
Unlimited Elements for Elementor PATCH
Reporter: CONTACT
|
6.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-92243 |
Ivory Search – WordPress Search Plugin
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-92538 |
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-92551 |
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-92826 |
EWWW Image Optimizer
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-103888 |
WPC Smart Quick View for WooCommerce
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-103909 |
Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-104313 |
WPC Estimated Delivery Date for WooCommerce
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-92974 |
Photo Gallery by 10Web – Mobile-Friendly Image Gallery
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-93896 |
WPFront Notification Bar
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-105112 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6
MEDIUM
|
VIEW RECORD |
| CVE-2026-18040 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
5.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-104474 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
5.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-100180 |
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress
Reporter: SECURITY
|
5.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-103421 |
WPMobile.App – Android and iOS App Builder
Reporter: SECURITY
|
5.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-103519 |
WP Ultimate Review
Reporter: SECURITY
|
5.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-104477 |
Product identification pending
Reporter: DISCLOSURE
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-105029 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-100149 |
WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons
Reporter: SECURITY
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-86832 |
MetForm PATCH
Reporter: CONTACT
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-92437 |
Mailchimp for WooCommerce PATCH
Reporter: CONTACT
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-11601 |
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System
Reporter: SECURITY
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-97873 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-105114 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-105117 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-105122 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-104475 |
Product identification pending
Reporter: DISCLOSURE
|
5.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-104479 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
5.1
MEDIUM
|
VIEW RECORD |
About the Vulnerability Pulse CVE Feed
The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.
How to Use the CVE Advisory Tracker
Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.
What Is a CVE Advisory?
A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.
CVE Analysis & Writeups
For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.