CVE-2026-81776
largeUnauthenticated Cross-Site Scripting (XSS) in WP QuickLaTeX WordPress plugin
WP QuickLaTeX, a WordPress plugin that renders LaTeX math expressions via the QuickLaTeX service, is affected by an unauthenticated cross-site scripting flaw (CWE-79) in all versions up to and including 3.8.8. Because the vulnerability requires no authentication, any unprivileged visitor can trigger it by supplying crafted input that the plugin renders on a page, and exploitation relies on a victim's browser loading the injected script (consistent with the User Interaction requirement in the CVSS score). An attacker who succeeds can execute arbitrary JavaScript in the context of the affected site, with the potential to steal or alter content visible to the victim user (scope-changed, low confidentiality and integrity impact per the CVSS vector). Any WordPress site running WP QuickLaTeX 3.8.8 or earlier is affected. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only a 0.2% chance of exploitation in the next 30 days.
What to do: Update WP QuickLaTeX to the latest release available on WordPress.org (any version newer than 3.8.8) as soon as practical. Until patched, restrict or sanitize untrusted LaTeX input on your site, and review comment/post content for embedded script or HTML that could have been injected through the plugin. Monitor the plugin's changelog and security feeds for a disclosed PoC or in-the-wild activity, since EPSS is currently low but may rise.
| QuickLaTeX (WordPress plugin) WP QuickLaTeX | <= 3.8.8 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.