What is CVE-2026-75091?
A Stored Cross-Site Scripting vulnerability exists in the Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress. All versions up to and including 5.7.1 are affected, allowing unauthenticated attackers to inject malicious scripts due to insufficient input sanitization and output escaping. Updating the plugin to the latest version is recommended.
Azərbaycanca: WordPress üçün "Quill Forms | Conversational Multi Step Forms, Surveys & quizzes" plaginində saxlanılmış XSS (Stored Cross-Site Scripting) zəifliyi aşkarlanıb. 5.7.1-ə qədər olan bütün versiyalar təsirlənir və autentifikasiya olunmamış hücumçulara xüsusi skriptlər yeritməyə imkan verir. Plaginin ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Quill Forms plugin for WordPress are affected by CVE-2026-75091?
All versions up to and including 5.7.1 are affected by this Stored XSS vulnerability.
What can an attacker achieve by exploiting CVE-2026-75091?
An unauthenticated attacker can inject malicious scripts due to insufficient input sanitization and output escaping.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.