PT-2026-95780 · WordPress · Quill Forms
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Quill Forms | Conversational Multi Step Forms, Surveys & quizzes versions prior to 5.7.2
Description
Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Stored Cross-Site Scripting (XSS), a technique where malicious scripts are permanently stored on the target server. The issue occurs via the Multiple Choice 'Other' value, enabling the injection of arbitrary web scripts. These scripts execute within the context of the WordPress admin results view, primarily targeting administrators who review submitted form entries.
Recommendations
Update Quill Forms | Conversational Multi Step Forms, Surveys & quizzes to version 5.7.2 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quill Forms