MathJax-LaTeX [mathjax-latex] < 1.2
unknown
Mathjax Latex plugin is prone to a cross-site request forgery. It allows to specify Javascript that will be loaded with each post. Also, it will be loaded onto the homepage of the WordPress blog.
Update the plugin.
- Affected:
- up to 1.2
- Fixed in:
- 1.2
- Disclosed:
- Mar 26, 2013
MathJax-LaTeX < 1.2 - Cross-Site Request Forgery
high
The MathJax LaTeX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.2. This is due to missing or incorrect nonce validation on the mathjax_plugin_options function. This may make it possible for unauthenticated attackers to arbitrarily change plugin settings via a forged request grant...
- CVSS:
- 8.8
- Affected:
- up to 1.2
- Fixed in:
- 1.2
- Disclosed:
- Mar 25, 2013
MathJax-LaTeX [mathjax-latex] < 1.2
unknown
The MathJax LaTeX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.2. This is due to missing or incorrect nonce validation on the mathjax_plugin_options function. This may make it possible for unauthenticated attackers to arbitrarily change plugin settings via a forged request grant...
- Affected:
- up to 1.2
- Fixed in:
- 1.2
- Disclosed:
- Mar 25, 2013
MathJax-LaTeX [mathjax-latex] < 1.2
unknown
The MathJax-LaTeX WordPress plugin was affected by a Setting Manipulation CSRF security vulnerability.
- Affected:
- up to 1.2
- Fixed in:
- 1.2
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database