Junglewise Threat Intelligence

CVE-2026-15664: Quill Forms Stored Cross-Site Scripting in Multiple Choice Other Value

CVE-2026-15664 · Severity: high · CVSS 7.2 · Published 2026-09-19

Executive brief

Quill Forms is a WordPress plugin that creates conversational forms and surveys. Attackers can inject malicious scripts into form responses that execute when administrators review submitted entries, potentially allowing account compromise or data theft from admin sessions.

Technical details

The plugin insufficiently sanitizes and escapes user input in the Multiple Choice block's "Other" field value, allowing stored XSS injection. Unauthenticated attackers can inject arbitrary JavaScript that executes in the admin panel context when form results are viewed. The vulnerability affects all versions up to and including 5.7.1.

Affected products

  • Quill Quill Forms up to and including 5.7.1

Timeline

  • 2026-09-19: disclosed

References