Junglewise Threat Intelligence

CVE-2026-81776: WP QuickLaTeX unauthenticated cross-site scripting

CVE-2026-81776 · Severity: high · CVSS 7.1 · Published 2026-09-03

Executive brief

WP QuickLaTeX is a WordPress plugin that renders LaTeX equations on websites. An unauthenticated cross-site scripting (XSS) vulnerability in versions 3.8.8 and earlier allows attackers to inject malicious scripts that can steal visitor data, hijack accounts, or redirect users to phishing sites without requiring any special privileges or authentication.

Technical details

The vulnerability is an unauthenticated cross-site scripting (XSS) flaw in WP QuickLaTeX plugin versions 3.8.8 and earlier. The vulnerability can be exploited by attackers to inject malicious JavaScript code into the affected website, though user interaction (such as clicking a malicious link or visiting a crafted page) may be required for successful exploitation in some scenarios. An attacker can leverage this to steal sensitive visitor data, hijack user accounts, or perform actions on behalf of users. As of the advisory publication date (September 2026), no official patch is available; mitigation via security plugins or hosting provider assistance is recommended.

Affected products

  • WP QuickLaTeX WP QuickLaTeX 3.8.8 and earlier

Timeline

  • 2026-09-03: disclosed
  • 2026-03-31: reported

References