WP QuickLaTeX
WP QuickLaTeX has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; 2 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high. 2024 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 3 of the records (100%).
2 of the records (67%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2026.
3 independent researchers contributed these findings, one record each. WP QuickLaTeX is installed on roughly 4,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.5.10.
CVE-2026-81776WP QuickLaTeX <= 3.8.8 - Unauthenticated Stored Cross-Site Scripting
Read the full analysisVulnerability Records
WP QuickLaTeX
Author
advanpix
Insert formulas & graphics in the posts and comments using native LaTeX shorthands directly in the text. Inline formulas, displayed equations auto-numbering, labeling and referencing, AMS-LaTeX, TikZ, custom LaTeX preamble. No LaTeX installation required. Easily customizable using UI page. Actively developed and maintained. Visit QuickLaTeX homepage for more info. Standard LaTeX expressions can be cut and pasted directly into WordPress posts, pages, and comments; display environments require no enclosures, other expressions require only a surrounding $..$ or \[..\]. No need for enclosing tags [latex] ... [/latex]. Correct vertical positioning of inline formulas relative to baseline of surrounding text. Say “NO” to jumpy equations produced by other plugins! SVG vector graphics support, so that formulas are crisp regardless of scaling in browser. (AMS)LaTeX displayed math environments support: equation, align, gather, multiline, flalign, alignat, etc. Automatic numbering of displayed equations. Override autonumbering with \tag{} LaTeX command. Equation hyper-referencing by standard LaTeX rules with \label{}, \ref{}. Custom LaTeX document preamble, allowing added \usepackage{} and \newcommand{}. TikZ and pgfplots graphics package support. Preview formulas in comments before publishing. Additionally AJAX Comment Preview plugin should be installed to enable this feature. Meaningful error messages for mistakes in LaTeX code. Precise font properties tuning: size, text and background color. Easy style customization using UI or CSS file. No LaTeX installation is required. QuickLaTeX.com automatically provides formula images, which are then cached on user’s server. Administrative settings page for setting global parameters; AJAX-ified. Just place LaTeX math expressions into your text and enable QuickLaTeX on the page by [latexpage] command. WP QuickLaTeX will convert them to high-quality images and embed into post. Inline formulas will be properly aligned with the text. Displayed equations will be auto-numbered by LaTeX rules. To see plugin in action please visit math-pages on my blog, e.g. Central Differences, Cubature formulas for the unit disk, Smooth noise robust differentiators, etc.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C