Calculated Fields Form - Authenticated (Contributor+) Stored Cross-Site Scripting via Form Settings vulnerability
medium
Authenticated (Contributor+) Stored Cross-Site Scripting via Form Settings vulnerability
- CVSS:
- 6.5
- Affected:
- up to 5.4.5.0
- Fixed in:
- 5.4.5.1
- Disclosed:
- Mar 13, 2026
Calculated Fields Form <= 5.4.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Form Settings
medium
The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form settings in all versions up to, and including, 5.4.5.0. This is due to insufficient capability checks on the form settings save handler and insufficient input sanitization of the `fcontent` field in `fhtml` field t...
- CVSS:
- 6.4
- Affected:
- up to 5.4.5.0
- Fixed in:
- 5.4.5.1
- Disclosed:
- Mar 12, 2026
CVE-2026-3986 on NVD →
Calculated Fields Form [calculated-fields-form] <= 5.4.4.1 (unfixed)
unknown
[en] Missing Authorization vulnerability in codepeople Calculated Fields Form calculated-fields-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Calculated Fields Form: from n/a through <= 5.4.4.1.
- Affected:
- up to 5.4.4.1
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-25368 on NVD →
Calculated Fields Form <= 5.4.4.1 - Missing Authorization
medium
The Calculated Fields Form plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.4.4.1. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 5.4.4.1
- Fixed in:
- 5.4.4.2
- Disclosed:
- Feb 16, 2026
CVE-2026-25368 on NVD →
Calculated Fields Form [calculated-fields-form] < 5.3.59
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in codepeople Calculated Fields Form allows Cross Site Request Forgery. This issue affects Calculated Fields Form: from n/a through 5.3.58.
- Affected:
- up to 5.3.59
- Fixed in:
- 5.3.59
- Disclosed:
- Jun 6, 2025
CVE-2025-49291 on NVD →
Calculated Fields Form <= 5.3.58 - Cross-Site Request Forgery
medium
The Calculated Fields Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.3.58. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a si...
- CVSS:
- 4.3
- Affected:
- up to 5.3.58
- Fixed in:
- 5.3.59
- Disclosed:
- Jun 5, 2025
CVE-2025-49291 on NVD →
Calculated Fields Form [calculated-fields-form] < 5.2.64
unknown
[en] The Calculated Fields Form WordPress plugin before 5.2.64 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 5.2.64
- Fixed in:
- 5.2.64
- Disclosed:
- May 15, 2025
CVE-2024-13382 on NVD →
Calculated Fields Form [calculated-fields-form] < 5.2.62
unknown
[en] The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 5.2.62
- Fixed in:
- 5.2.62
- Disclosed:
- May 1, 2025
CVE-2024-13381 on NVD →
Calculated Fields Form [calculated-fields-form] < 5.2.62
unknown
[en] The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 5.2.62
- Fixed in:
- 5.2.62
- Disclosed:
- Apr 29, 2025
CVE-2024-12273 on NVD →
Calculated Fields Form <= 5.2.61 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.2.61 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to...
- CVSS:
- 4.4
- Affected:
- up to 5.2.61
- Fixed in:
- 5.2.62
- Disclosed:
- Apr 9, 2025
CVE-2024-13381 on NVD →
Calculated Fields Form <= 5.2.61 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.2.61 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to...
- CVSS:
- 4.4
- Affected:
- up to 5.2.61
- Fixed in:
- 5.2.62
- Disclosed:
- Apr 8, 2025
CVE-2024-12273 on NVD →
Calculated Fields Form <= 5.2.63 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.2.63 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to...
- CVSS:
- 4.4
- Affected:
- up to 5.2.63
- Fixed in:
- 5.2.64
- Disclosed:
- Mar 2, 2025
CVE-2024-13382 on NVD →
Calculated Fields Form [calculated-fields-form] < 5.2.64
unknown
[en] The Calculated Fields Form plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 5.2.63. This is due to unlimited height and width parameters for CAPTCHA images. This makes it possible for unauthenticated attackers to send multiple requests with large values, resulting in sl...
- Affected:
- up to 5.2.64
- Fixed in:
- 5.2.64
- Disclosed:
- Dec 17, 2024
CVE-2024-12601 on NVD →
Calculated Fields Form <= 5.2.63 - Denial of Service
medium
The Calculated Fields Form plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 5.2.63. This is due to unlimited height and width parameters for CAPTCHA images. This makes it possible for unauthenticated attackers to send multiple requests with large values, resulting in slowing...
- CVSS:
- 5.3
- Affected:
- up to 5.2.63
- Fixed in:
- 5.2.64
- Disclosed:
- Dec 16, 2024
CVE-2024-12601 on NVD →
Calculated Fields Form [calculated-fields-form] < 5.2.46
unknown
[en] The Calculated Fields Form plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 5.2.45. This is due to the plugin not properly neutralizing HTML elements from submitted forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that will render when t...
- Affected:
- up to 5.2.46
- Fixed in:
- 5.2.46
- Disclosed:
- Oct 17, 2024
CVE-2024-9940 on NVD →
Calculated Fields Form <= 5.2.45 - HTML Injection
medium
The Calculated Fields Form plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 5.2.45. This is due to the plugin not properly neutralizing HTML elements from submitted forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that will render when the ad...
- CVSS:
- 5.3
- Affected:
- up to 5.2.45
- Fixed in:
- 5.2.46
- Disclosed:
- Oct 16, 2024
CVE-2024-9940 on NVD →
Calculated Fields Form [calculated-fields-form] < 1.1.121
unknown
[en] Missing Authorization vulnerability in CodePeople Calculated Fields Form allows Functionality Misuse.This issue affects Calculated Fields Form: from n/a through 1.1.120.
- Affected:
- up to 1.1.121
- Fixed in:
- 1.1.121
- Disclosed:
- Jun 3, 2024
CVE-2023-26523 on NVD →
Calculated Fields Form [calculated-fields-form] < 1.2.55
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodePeople Calculated Fields Form allows Reflected XSS.This issue affects Calculated Fields Form: from n/a through 1.2.54.
- Affected:
- up to 1.2.55
- Fixed in:
- 1.2.55
- Disclosed:
- Mar 27, 2024
CVE-2024-29759 on NVD →
Calculated Fields Form <= 1.2.54 - Reflected Cross-Site Scripting
medium
The Calculated Fields Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions up to, and including, 1.2.54 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
- CVSS:
- 6.1
- Affected:
- up to 1.2.54
- Fixed in:
- 1.2.55
- Disclosed:
- Mar 25, 2024
CVE-2024-29759 on NVD →
Calculated Fields Form [calculated-fields-form] < 5.1.57
unknown
[en] The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form page href parameter in all versions up to, and including, 5.1.56 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...
- Affected:
- up to 5.1.57
- Fixed in:
- 5.1.57
- Disclosed:
- Mar 13, 2024
CVE-2024-2020 on NVD →
Calculated Fields Form Professional <= 5.1.56 - Unauthenticated Stored Cross-Site Scripting
high
The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form page href parameter in all versions up to, and including, 5.1.56 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in p...
- CVSS:
- 7.2
- Affected:
- up to 5.1.56
- Fixed in:
- 5.1.57
- Disclosed:
- Mar 1, 2024
CVE-2024-2020 on NVD →
Calculated Fields Form [calculated-fields-form] < 1.2.53
unknown
[en] The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's CP_CALCULATED_FIELDS shortcode in all versions up to, and including, 1.2.52 due to insufficient input sanitization and output escaping on user supplied 'location' attribute. This makes it possible for auth...
- Affected:
- up to 1.2.53
- Fixed in:
- 1.2.53
- Disclosed:
- Feb 2, 2024
CVE-2024-0963 on NVD →
Calculated Fields Form <= 1.2.52 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's CP_CALCULATED_FIELDS shortcode in all versions up to, and including, 1.2.52 due to insufficient input sanitization and output escaping on user supplied 'location' attribute. This makes it possible for authentic...
- CVSS:
- 6.4
- Affected:
- up to 1.2.52
- Fixed in:
- 1.2.53
- Disclosed:
- Feb 1, 2024
CVE-2024-0963 on NVD →
Calculated Fields Form [calculated-fields-form] < 1.1.151
unknown
[en] The Calculated Fields Form WordPress plugin before 1.1.151 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 1.1.151
- Fixed in:
- 1.1.151
- Disclosed:
- Jan 16, 2024
CVE-2023-0389 on NVD →
Calculated Fields Form [calculated-fields-form] < 1.2.41
unknown
[en] The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.40 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above...
- Affected:
- up to 1.2.41
- Fixed in:
- 1.2.41
- Disclosed:
- Jan 11, 2024
CVE-2023-6446 on NVD →
Calculated Fields Form [calculated-fields-form] < 1.2.29
unknown
[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CodePeople Calculated Fields Form.This issue affects Calculated Fields Form: from n/a through 1.2.28.
- Affected:
- up to 1.2.29
- Fixed in:
- 1.2.29
- Disclosed:
- Dec 29, 2023
CVE-2023-51517 on NVD →
Calculated Fields Form <= 1.2.28 - Authenticated (Contributor+) Open Redirect via Shortcode
medium
The Calculated Fields Form plugin for WordPress is vulnerable to Open Redirect via the plugin's shortcode(s) in all versions up to 1.2.29 (exclusive) due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and abov...
- CVSS:
- 4.3
- Affected:
- up to 1.2.28
- Fixed in:
- 1.2.29
- Disclosed:
- Dec 27, 2023
CVE-2023-51517 on NVD →
Calculated Fields Form <= 1.2.40 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.40 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to...
- CVSS:
- 4.4
- Affected:
- up to 1.2.40
- Fixed in:
- 1.2.41
- Disclosed:
- Dec 5, 2023
CVE-2023-6446 on NVD →
Calculated Fields Form <= 1.1.120 - Cross-Site Request Forgery
medium
The Calculated Fields Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.120. This is due to missing or incorrect nonce validation on the feedback_action function. This makes it possible for unauthenticated attackers to leave plugin feedback on the site owner's b...
- CVSS:
- 4.3
- Affected:
- up to 1.1.120
- Fixed in:
- 1.1.121
- Disclosed:
- Mar 2, 2023
CVE-2023-26523 on NVD →
Calculated Fields Form <= 1.1.120 - Missing Authorization to Feedback Submission
medium
The Calculated Fields Form plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on the feedback_action function in versions up to, and including, 1.1.120. This makes it possible for authenticated attackers with subscriber-level access to provide plugin feedback on...
- CVSS:
- 4.3
- Affected:
- up to 1.1.120
- Fixed in:
- 1.1.121
- Disclosed:
- Feb 28, 2023
CVE-2023-26523 on NVD →
Calculated Fields Form <= 1.1.150 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.1.150 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inj...
- CVSS:
- 4.4
- Affected:
- up to 1.1.150
- Fixed in:
- 1.1.151
- Disclosed:
- Feb 22, 2023
CVE-2023-0389 on NVD →
Calculated Fields Form <= 1.0.353 - Authenticated Stored Cross-Site Scripting
medium
The Calculated Fields Form plugin through 1.0.353 for WordPress suffers from multiple Stored XSS vulnerabilities present in the input forms. These can be exploited by an authenticated user.
- CVSS:
- 5.4
- Affected:
- up to 1.0.353
- Fixed in:
- 1.0.354
- Disclosed:
- Jan 22, 2020
CVE-2020-7228 on NVD →
Calculated Fields Form [calculated-fields-form] < 1.0.354
unknown
[en] The Calculated Fields Form plugin through 1.0.353 for WordPress suffers from multiple Stored XSS vulnerabilities present in the input forms. These can be exploited by an authenticated user.
- Affected:
- up to 1.0.354
- Fixed in:
- 1.0.354
- Disclosed:
- Jan 22, 2020
CVE-2020-7228 on NVD →
Calculated Fields Form <= 1.0.11 - Cross-Site Request Forgery to SQL Injection
critical
The Calculated Fields Form plugin for WordPress is vulnerable to SQL Injection via Cross-Site Request Forgery in versions up to, and including, 1.0.11 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated att...
- CVSS:
- 9.8
- Affected:
- up to 1.0.11
- Fixed in:
- 1.0.12
- Disclosed:
- Mar 2, 2015
Calculated Fields Form [calculated-fields-form] < 1.0.11
unknown
Calculated Fields Form plugin is prone to a remote SQL injection vulnerability that allows an attacker to execute SQL queries into database.
Upgrade the plugin.
- Affected:
- up to 1.0.11
- Fixed in:
- 1.0.11
- Disclosed:
- Mar 2, 2015
Calculated Fields Form [calculated-fields-form] < 1.0.12
unknown
The Calculated Fields Form plugin for WordPress is vulnerable to SQL Injection via Cross-Site Request Forgery in versions up to, and including, 1.0.11 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated att...
- Affected:
- up to 1.0.12
- Fixed in:
- 1.0.12
- Disclosed:
- Mar 2, 2015
Calculated Fields Form [calculated-fields-form] < 1.0.12
unknown
The Calculated Fields Form WordPress plugin was affected by a SQL Injection via CSRF security vulnerability.
- Affected:
- up to 1.0.12
- Fixed in:
- 1.0.12