Impact
The vulnerability is an unauthenticated XSS in WordPress Quill Forms plugin versions ≤ 5.7.1. Based on the description, it is inferred that an attacker could inject malicious scripts into form data or other plugin outputs, which would then execute in the victim's browser. The flaw comes from a failure to sanitise user input, a classic CWE‑79 weakness, and it is inferred that this could lead to cookie theft, page defacement, and phishing redirects. Based on the description, it is inferred that the impact is confined to the client’s browser context but could affect any visitor who views the vulnerable form.
Affected Systems
The affected product is the Quill Forms plugin by Mohamed Magdy, up to and including version 5.7.1. Any WordPress site running the plugin in these versions is vulnerable until it is upgraded.
Risk and Exploitability
The CVSS base score of 7.1 signals a high risk, with no authentication required and an exploitation that can occur through normal web traffic. The EPSS score is unavailable, and the vulnerability is not listed in CISA KEV. Based on the information, it is inferred that no public exploits are known, but the absence from KEV does not guarantee that no exploits exist. Based on the description, it is inferred that an attacker could exploit the flaw by submitting malicious payloads via form fields or other inputs that bypass sanitisation, with those payloads rendered when the form output is viewed in browsers.
OpenCVE Enrichment