ZeroHour

CVE-2026-81776

large

Unauthenticated Cross-Site Scripting (XSS) in WP QuickLaTeX WordPress plugin

CVSS 3.1
7.1 high
EPSS
<1%p8
Published
()
Modified
AI analysis

WP QuickLaTeX, a WordPress plugin that renders LaTeX math expressions via the QuickLaTeX service, is affected by an unauthenticated cross-site scripting flaw (CWE-79) in all versions up to and including 3.8.8. Because the vulnerability requires no authentication, any unprivileged visitor can trigger it by supplying crafted input that the plugin renders on a page, and exploitation relies on a victim's browser loading the injected script (consistent with the User Interaction requirement in the CVSS score). An attacker who succeeds can execute arbitrary JavaScript in the context of the affected site, with the potential to steal or alter content visible to the victim user (scope-changed, low confidentiality and integrity impact per the CVSS vector). Any WordPress site running WP QuickLaTeX 3.8.8 or earlier is affected. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only a 0.2% chance of exploitation in the next 30 days.

What to do: Update WP QuickLaTeX to the latest release available on WordPress.org (any version newer than 3.8.8) as soon as practical. Until patched, restrict or sanitize untrusted LaTeX input on your site, and review comment/post content for embedded script or HTML that could have been injected through the plugin. Monitor the plugin's changelog and security feeds for a disclosed PoC or in-the-wild activity, since EPSS is currently low but may rise.

Affected
QuickLaTeX (WordPress plugin) WP QuickLaTeX<= 3.8.8
Estimated exposure
large≈10,000+ WordPress sites (WordPress.org lists the plugin at 10,000+ active installs) — The WordPress.org plugin directory lists WP QuickLaTeX at roughly 10,000+ active installations, and only a subset of those sites serve attacker-controllable LaTeX input to unauthenticated visitors, making 10k–100k a reasonable upper band.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions.

Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.