high · CVSS v3 7.2 · EPSS 0.00386
CVE-2026-15664
The Quill Forms WordPress plugin is vulnerable to stored XSS via the 'Other' field in multiple choice questions. Unauthenticated attackers c
Overview
The Quill Forms WordPress plugin is vulnerable to stored XSS via the 'Other' field in multiple choice questions. Unauthenticated attackers can inject scripts that execute when administrators view form results, potentially hijacking sessions or defacing pages. This flaw can compromise the confidentiality, integrity, and availability of the site’s admin interface.
Description
The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple Choice 'Other' Value in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected script executes in the context of the WordPress admin results view, making administrators the primary target when reviewing submitted form entries.
Impact
Confidentiality: attackers can steal admin session cookies. Integrity: injected scripts can alter admin pages or data. Availability: potential for defacement or denial of service. Primary impact on WordPress site administrators reviewing form entries.
Remediation
Update Quill Forms to the latest version (≥5.7.2). If updating is not possible, disable the 'Other' option or enforce input sanitization via plugin settings. Deploy a WAF rule to block script payloads in form submissions. Enable two‑factor authentication for all admin accounts.
Risk context
Severity is high with a CVSS v3 score of 7.2 and an EPSS of 0.00386, indicating a low probability but high impact event. Prompt patching and monitoring are advised.
Affected products
- Quill Forms WordPress plugin
Scores
- Severity
- high
- CVSS v2
- 6.4
- CVSS v3
- 7.2
- CVSS v4
- —
- EPSS
- 0.00386