Executive brief
Quill Forms is a popular WordPress plugin used to build interactive forms and surveys. Unauthenticated attackers can inject malicious code into affected websites, allowing them to steal visitor data, hijack user accounts, or redirect users to phishing pages. The vulnerability affects all versions up to 5.7.1 and requires a patch to version 5.7.2 or later to resolve.
Technical details
This is a reflected or stored Cross Site Scripting (XSS) vulnerability in the Quill Forms WordPress plugin versions 5.7.1 and earlier. The vulnerability allows unauthenticated attackers to inject malicious scripts, though successful exploitation requires user interaction (e.g., clicking a malicious link or visiting a crafted page). The attack vector is network-based and does not require administrative privileges. Attackers can achieve arbitrary code execution in the victim's browser context, leading to session hijacking, credential theft, or malware distribution. The vulnerability has been patched in version 5.7.2.
Affected products
- Quill Forms Quill Forms <=5.7.1
Timeline
- 2026-08-18: disclosed: Published on NVD
- 2026-08-14: patched: Version 5.7.2 released with patch