CVE-2026-75091Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-18: 2Technical Details · 2026-08-18: 208-18
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-75091 The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and incl… https://www.cve.org/CVERecord?id=CVE-2026-75091

    Post summary

    The post announces that Quill Forms for WordPress is vulnerable to stored XSS across all versions up to the current one, with no PoC, exploit, or patch mentioned.

    00000670
    58.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-75091 Stored XSS in Quill Forms WordPress Plugin Up To 5.7.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-75091

    Post summary

    The post announces a stored XSS vulnerability (CVE-2026-75091) affecting Quill Forms WordPress plugin versions up to 5.7.1, but it provides no exploits, patches, or evidence of active exploitation.

    00000109
    4.1K followersView on X

Explore more