Executive brief
Quill Forms is a WordPress plugin that creates conversational forms and surveys. Attackers can inject malicious scripts into form responses that execute when administrators review submitted entries, potentially allowing account compromise or data theft from admin sessions.
Technical details
The plugin insufficiently sanitizes and escapes user input in the Multiple Choice block's "Other" field value, allowing stored XSS injection. Unauthenticated attackers can inject arbitrary JavaScript that executes in the admin panel context when form results are viewed. The vulnerability affects all versions up to and including 5.7.1.
Affected products
- Quill Quill Forms up to and including 5.7.1
Timeline
- 2026-09-19: disclosed