Retour à la veille

CVE-2026-15664

Publié : 19 septembre 2026
Modifié : 19 septembre 2026
Lien officiel NVD
Score CVSS
7.2
HIGH

Description détaillée

The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple Choice 'Other' Value in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected script executes in the context of the WordPress admin results view, making administrators the primary target when reviewing submitted form entries.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Références et Patchs

https://plugins.trac.wordpress.org/browser/quillforms/tags/5.6.1/includes/abstracts/class-block-type.php#L402https://plugins.trac.wordpress.org/browser/quillforms/tags/5.6.1/includes/blocks/multiple-choice/class-multiple-choice-block.php#L199https://plugins.trac.wordpress.org/browser/quillforms/tags/5.6.1/includes/class-form-submission.php#L111https://plugins.trac.wordpress.org/browser/quillforms/tags/5.6.1/includes/class-form-submission.php#L194https://plugins.trac.wordpress.org/browser/quillforms/tags/5.6.1/includes/class-form-submission.php#L262https://plugins.trac.wordpress.org/browser/quillforms/tags/5.6.1/includes/rest-api/controllers/v1/class-rest-entry-controller.php#L191https://plugins.trac.wordpress.org/browser/quillforms/tags/5.7.0/includes/abstracts/class-block-type.php#L402https://plugins.trac.wordpress.org/browser/quillforms/tags/5.7.0/includes/blocks/multiple-choice/class-multiple-choice-block.php#L199https://plugins.trac.wordpress.org/browser/quillforms/tags/5.7.0/includes/class-form-submission.php#L111https://plugins.trac.wordpress.org/browser/quillforms/tags/5.7.0/includes/class-form-submission.php#L194https://plugins.trac.wordpress.org/browser/quillforms/tags/5.7.0/includes/class-form-submission.php#L262https://plugins.trac.wordpress.org/browser/quillforms/tags/5.7.0/includes/rest-api/controllers/v1/class-rest-entry-controller.php#L191https://plugins.trac.wordpress.org/changeset?reponame=&old=3663009%40quillforms&new=3663009%40quillformshttps://www.wordfence.com/threat-intel/vulnerabilities/id/1261881f-7a04-47fb-8176-6a9ac2088f8d?source=cve

Dernières Vulnérabilités

CVE-2026-9858

The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.4 via the wxp_order_shipment, wxp_order_item_shipment, and wxp_order_set_shipped AJAX actions. This is due to the AJAX handlers in woocommerce-partial-shipment.php (registered at lines 60–62 and implemented at lines 228, 263, and 291) lacking both capability checks and nonce verification, and not validating the calling user's ownership of the supplied order_id. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary order item details (names, quantities, shipped counts) belonging to any customer and to modify the shipment status / shipped quantities of any order, which can also trigger order status transitions via the wxp_order_status action.

VOIR DÉTAILS

CVE-2026-9766

The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify arbitrary WooCommerce product metadata, including Empik logistic class (_empik_logistic_klass), product state (_empik_product_state, _empik_product_state_all_variants), and Empik export and offer flags on any product in the store.

VOIR DÉTAILS

CVE-2026-9613

The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.65. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to create and cancel real shipping orders through the external logistics API using the store's stored authentication token, modify arbitrary WooCommerce order post meta on any order, overwrite the plugin's stored API token, and trigger shipping notification emails to customers.

VOIR DÉTAILS