Impact
The Quill Forms plugin for WordPress can store arbitrary script code due to insufficient sanitization of form inputs and lack of output escaping. A single stored XSS payload is injected into any rendered form page, causing the code to execute automatically in the browsers of visitors who view the affected form. This allows an attacker to hijack user sessions, steal cookies, deface content, or perform further phishing actions without needing any authentication on the target site.
Affected Systems
The vulnerability affects the mdmag:Quill Forms WordPress plugin, versions up to and including 5.7.1. Users who are running any of these releases on a WordPress installation are potentially impacted.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity. With no EPSS data available, the past exploitation probability is unknown, and the vulnerability is not listed in the CISA KEV catalog. An attacker can exploit it by simply visiting a page containing a stored form script, making it an unauthenticated attack that requires no special privileges or credentials.
OpenCVE Enrichment