Junglewise Threat Intelligence

CVE-2026-56039: Quick Interest Slider Reflected XSS

CVE-2026-56039 · Severity: high · CVSS 7.1 · Published 2026-06-26

Executive brief

Quick Interest Slider is a WordPress plugin used to display interactive interest rate calculators and sliders on websites. A security flaw in versions 3.1.6 and earlier allows unauthenticated attackers to inject malicious scripts into the site. If a user clicks a specially crafted link, the attacker could steal session information, redirect users to malicious websites, or deface the site's content.

Technical details

The Quick Interest Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on user-supplied data. An unauthenticated attacker can exploit this by sending a crafted link to a user; when the user visits the link, the malicious script executes within the context of their browser session. This can lead to the theft of sensitive information such as session cookies or the performance of unauthorized actions on behalf of the user. The vulnerability affects all versions up to and including 3.1.6.

Affected products

  • Quick Interest Slider Quick Interest Slider <= 3.1.6

Timeline

  • 2026-06-26: disclosed

References