rootpwn

high · CVSS v3 7.2 · EPSS 0.00386

CVE-2026-15664

The Quill Forms WordPress plugin is vulnerable to stored XSS via the 'Other' field in multiple choice questions. Unauthenticated attackers c

Overview

The Quill Forms WordPress plugin is vulnerable to stored XSS via the 'Other' field in multiple choice questions. Unauthenticated attackers can inject scripts that execute when administrators view form results, potentially hijacking sessions or defacing pages. This flaw can compromise the confidentiality, integrity, and availability of the site’s admin interface.

Description

The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple Choice 'Other' Value in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected script executes in the context of the WordPress admin results view, making administrators the primary target when reviewing submitted form entries.

Impact

Confidentiality: attackers can steal admin session cookies. Integrity: injected scripts can alter admin pages or data. Availability: potential for defacement or denial of service. Primary impact on WordPress site administrators reviewing form entries.

Remediation

Update Quill Forms to the latest version (≥5.7.2). If updating is not possible, disable the 'Other' option or enforce input sanitization via plugin settings. Deploy a WAF rule to block script payloads in form submissions. Enable two‑factor authentication for all admin accounts.

Risk context

Severity is high with a CVSS v3 score of 7.2 and an EPSS of 0.00386, indicating a low probability but high impact event. Prompt patching and monitoring are advised.

Affected products

  • Quill Forms WordPress plugin

Scores

Severity
high
CVSS v2
6.4
CVSS v3
7.2
CVSS v4
EPSS
0.00386

XSS WordPress StoredXSS AdminTarget QuillForms HighSeverity

← All CVEs