CVE-2026-81776: WordPress WP QuickLaTeX plugin <= 3.8.8 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP QuickLaTeX pluginto a version that resolves this vulnerability.Fixed in 3.8.8
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges. Exploitation still requires user interaction, as reflected by the UI:R vector.
Which installations are affected?
WP QuickLaTeX versions 3.8.8 and earlier are affected according to the available information. The data does not identify a fixed version or any configuration prerequisites.
What impact can successful exploitation have?
Successful cross-site scripting can affect confidentiality, integrity, and availability at low impact levels. The CVSS vector also indicates that the impact may extend beyond the vulnerable component's security scope.