Impact
The Vulnerability arises from the Quill Forms WordPress plugin’s failure to sanitize and escape the text supplied to the "Other" field of multiple‑choice blocks. A malicious payload placed in that field is stored in the database and later rendered in the WordPress admin results view without proper sanitation. The result is that any regular JavaScript inserted by an attacker will execute whenever an administrator opens a form submission, allowing credential theft, session hijacking, or other privilege‑escalating actions.
Affected Systems
All WordPress installations that have the Quill Forms plugin by mdmag with a version of 5.7.1 or earlier are affected. Sites that use the plugin to build conversational multi‑step forms, surveys, or quizzes are at risk.
Risk and Exploitability
The CVSS score of 7.2 categorizes this as high severity, while the EPSS score of less than 1% shows a low current exploitation probability. The flaw is not listed in the CISA KEV catalog. Attackers need no authentication beyond submitting a crafted form entry; the malicious script is persisted and subsequently executed when an admin views the entry, thereby compromising the authenticity, confidentiality, or integrity of the admin session.
OpenCVE Enrichment