{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/quill-forms/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:quill_forms:conversational_multi_step_forms_surveys_quizzes:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-15664"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Quill Forms | Conversational Multi Step Forms, Surveys \u0026 quizzes (\u003c= 5.7.1)"],"_cs_severities":["high"],"_cs_tags":["wordpress","xss","web-application"],"_cs_type":"advisory","_cs_vendors":["Quill Forms"],"content_html":"\u003cp\u003eThe Quill Forms | Conversational Multi Step Forms, Surveys \u0026amp; quizzes plugin for WordPress (versions 5.7.1 and below) contains a stored cross-site scripting (XSS) vulnerability. The issue arises from insufficient sanitization and escaping of the 'Other' value field within Multiple Choice form elements. This allows an unauthenticated remote attacker to submit malicious payloads through publicly accessible forms. When a WordPress administrator accesses the form results page within the dashboard, the payload is rendered and executes in the context of their active session. This can lead to unauthorized actions performed on behalf of the administrator, such as creating new administrative accounts, modifying site settings, or exfiltrating sensitive session tokens.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability targets administrative accounts reviewing form submissions. Successful exploitation grants attackers the ability to execute arbitrary JavaScript within the WordPress admin dashboard, potentially leading to full site takeover.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the Quill Forms plugin to the latest patched version immediately. Monitor web server logs for HTTP POST requests to form submission endpoints containing JavaScript keywords or HTML tags within the 'Other' input parameters.\u003c/p\u003e\n","date_modified":"2026-09-19T10:11:01Z","date_published":"2026-09-19T10:11:01Z","id":"https://feed.craftedsignal.io/briefs/2026-09-quill-forms-xss/","summary":"The Quill Forms WordPress plugin (\u003c= 5.7.1) contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious JavaScript via form entry fields.","title":"Stored XSS in Quill Forms WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-quill-forms-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Quill Forms","version":"https://jsonfeed.org/version/1.1"}