Description
The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple Choice 'Other' Value in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected script executes in the context of the WordPress admin results view, making administrators the primary target when reviewing submitted form entries.
Published: 2026-09-19
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The Vulnerability arises from the Quill Forms WordPress plugin’s failure to sanitize and escape the text supplied to the "Other" field of multiple‑choice blocks. A malicious payload placed in that field is stored in the database and later rendered in the WordPress admin results view without proper sanitation. The result is that any regular JavaScript inserted by an attacker will execute whenever an administrator opens a form submission, allowing credential theft, session hijacking, or other privilege‑escalating actions.

Affected Systems

All WordPress installations that have the Quill Forms plugin by mdmag with a version of 5.7.1 or earlier are affected. Sites that use the plugin to build conversational multi‑step forms, surveys, or quizzes are at risk.

Risk and Exploitability

The CVSS score of 7.2 categorizes this as high severity, while the EPSS score of less than 1% shows a low current exploitation probability. The flaw is not listed in the CISA KEV catalog. Attackers need no authentication beyond submitting a crafted form entry; the malicious script is persisted and subsequently executed when an admin views the entry, thereby compromising the authenticity, confidentiality, or integrity of the admin session.

Generated by OpenCVE AI on September 19, 2026 at 23:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Quill Forms to a version newer than 5.7.1 where the stored XSS issue has been fixed.
  • If an upgrade cannot be performed immediately, deactivate the plugin or delete all form entries that contain an "Other" option to stop new malicious code from being stored.
  • Implement additional safeguards such as enforcing HTTPS for the WordPress admin area and adding a Web Application Firewall rule that blocks script tags in form submissions as a temporary safeguard.

Generated by OpenCVE AI on September 19, 2026 at 23:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://plugins.trac.wordpress.org/browser/quillforms/tags/5.6.1/includes/abstracts/class-block-type.php#L402 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/quillforms/tags/5.6.1/includes/blocks/multiple-choice/class-multiple-choice-block.php#L199 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/quillforms/tags/5.6.1/includes/class-form-submission.php#L111 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/quillforms/tags/5.6.1/includes/class-form-submission.php#L194 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/quillforms/tags/5.6.1/includes/class-form-submission.php#L262 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/quillforms/tags/5.6.1/includes/rest-api/controllers/v1/class-rest-entry-controller.php#L191 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/quillforms/tags/5.7.0/includes/abstracts/class-block-type.php#L402 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/quillforms/tags/5.7.0/includes/blocks/multiple-choice/class-multiple-choice-block.php#L199 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/quillforms/tags/5.7.0/includes/class-form-submission.php#L111 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/quillforms/tags/5.7.0/includes/class-form-submission.php#L194 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/quillforms/tags/5.7.0/includes/class-form-submission.php#L262 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/quillforms/tags/5.7.0/includes/rest-api/controllers/v1/class-rest-entry-controller.php#L191 cve-icon cve-icon
https://plugins.trac.wordpress.org/changeset?reponame=&old=3663009%40quillforms&new=3663009%40quillforms cve-icon cve-icon
https://www.wordfence.com/threat-intel/vulnerabilities/id/1261881f-7a04-47fb-8176-6a9ac2088f8d?source=cve cve-icon cve-icon
History

Sun, 20 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Mdmag
Mdmag quill Forms | Conversational Multi Step Forms, Surveys & Quizzes
Wordpress
Wordpress wordpress
Vendors & Products Mdmag
Mdmag quill Forms | Conversational Multi Step Forms, Surveys & Quizzes
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple Choice 'Other' Value in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected script executes in the context of the WordPress admin results view, making administrators the primary target when reviewing submitted form entries.
Title Quill Forms | Conversational Multi Step Forms, Surveys & quizzes <= 5.7.1 - Unauthenticated Stored Cross-Site Scripting via Multiple Choice 'Other' Value
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Mdmag Quill Forms | Conversational Multi Step Forms, Surveys & Quizzes
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:01:25.071Z

Reserved: 2026-07-13T20:41:30.078Z

Link: CVE-2026-15664

cve-icon Vulnrichment

Updated: 2026-09-19T13:55:23.623Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T08:16:52.763

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-15664

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:00:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')