CVE-2026-103909 Calculated Fields Form 反射型 DOM XSS 漏洞
影响攻击者可诱骗用户触发恶意脚本执行
WordPress 插件 Calculated Fields Form(AI Form Builder)存在反射型 DOM 型跨站脚本漏洞,影响 5.5.1.5 及之前所有版本。漏洞源于对通过 URL 传入的参数缺乏充分的输入过滤与输出转义,未认证攻击者可注入任意 Web 脚本。
影响范围
Calculated Fields Form 插件所有版本至 5.5.1.5(含)。
漏洞详情
漏洞类型为反射型 DOM-Based XSS,成因是插件对 URL 中传入的参数未做充分净化与转义,导致恶意脚本被写入页面 DOM 并执行。利用需目标站点存在公开可访问的表单,且管理员至少配置了两个使用 url.<name> 预定义值并在拼接公式中共同使用的字段,攻击者据此构造链接诱骗用户点击即可触发。
利用条件与风险
利用前提是站点存在符合上述配置的公开表单,且需诱导用户点击恶意链接,属于需要用户交互的中危漏洞,实战中可用于会话劫持或页面篡改。
修复建议
建议升级至官方修复版本;暂无公开信息时,可临时限制公开表单的敏感字段配置或对 URL 参数进行额外过滤。
The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the ‘arbitrary (whichever names the admin bound via url.)’ parameter in all versions up to, and including, 5.5.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires the targeted site to host a publicly accessible form in which an administrator has configured at least two fields with url.<name> predefined values that are used together in a concatenation equation — a plausible but not universal configuration.