Stored Cross-Site Scripting in Quill Forms Plugin for WordPress
CVE-2026-75091
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 August 2026
What is CVE-2026-75091?
The Quill Forms plugin for WordPress has a vulnerability that allows unauthenticated attackers to execute malicious scripts via Stored Cross-Site Scripting (XSS). This occurs in all versions up to 5.7.1 due to insufficient input sanitization and output escaping, enabling attackers to inject arbitrary web scripts into pages that will execute when accessed by users.
Affected Version(s)
Quill Forms | Conversational Multi Step Forms, Surveys & quizzes 0 <= 5.7.1