<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Quill Forms | Conversational Multi Step Forms, Surveys &amp; Quizzes (&lt;= 5.7.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/quill-forms--conversational-multi-step-forms-surveys--quizzes--5.7.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 19 Sep 2026 10:11:01 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/quill-forms--conversational-multi-step-forms-surveys--quizzes--5.7.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in Quill Forms WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-09-quill-forms-xss/</link><pubDate>Sat, 19 Sep 2026 10:11:01 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-quill-forms-xss/</guid><description>The Quill Forms WordPress plugin (&lt;= 5.7.1) contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious JavaScript via form entry fields.</description><content:encoded><![CDATA[<p>The Quill Forms | Conversational Multi Step Forms, Surveys &amp; quizzes plugin for WordPress (versions 5.7.1 and below) contains a stored cross-site scripting (XSS) vulnerability. The issue arises from insufficient sanitization and escaping of the 'Other' value field within Multiple Choice form elements. This allows an unauthenticated remote attacker to submit malicious payloads through publicly accessible forms. When a WordPress administrator accesses the form results page within the dashboard, the payload is rendered and executes in the context of their active session. This can lead to unauthorized actions performed on behalf of the administrator, such as creating new administrative accounts, modifying site settings, or exfiltrating sensitive session tokens.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability targets administrative accounts reviewing form submissions. Successful exploitation grants attackers the ability to execute arbitrary JavaScript within the WordPress admin dashboard, potentially leading to full site takeover.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update the Quill Forms plugin to the latest patched version immediately. Monitor web server logs for HTTP POST requests to form submission endpoints containing JavaScript keywords or HTML tags within the 'Other' input parameters.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>xss</category><category>web-application</category></item></channel></rss>