Impact
The WP QuickLaTeX plugin up to version 3.8.8 contains an unauthenticated Cross Site Scripting flaw that allows an attacker to inject arbitrary JavaScript into pages rendered by the plugin. This flaw enables client‑side code execution in the browsers of any visitors who view the affected content, leading to potential client‑side compromise of users through malicious scripts.
Affected Systems
Any WordPress site that has the advanpix WP QuickLaTeX plugin installed with a version of 3.8.8 or earlier is affected. The vulnerability is active for all such deployments regardless of user authentication.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity level. Because the flaw is unauthenticated, an attacker only needs the ability to deliver input that the plugin processes, such as through a publicly accessible URL or form. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, so no widespread exploitation has been reported yet. The risk remains high due to the ability to run arbitrary client‑side code on visitors' browsers.
OpenCVE Enrichment