plugin

Mathjax Latex Vulnerabilities

4 known security issues reported for the Mathjax Latex WordPress plugin. Most recent disclosed Mar 26, 2013.

1 high

Running Mathjax Latex on your site? Check whether your installed version is affected.

Scan your site free

MathJax-LaTeX [mathjax-latex] < 1.2

unknown

Mathjax Latex plugin is prone to a cross-site request forgery. It allows to specify Javascript that will be loaded with each post. Also, it will be loaded onto the homepage of the WordPress blog. Update the plugin.

Affected:
up to 1.2
Fixed in:
1.2
Disclosed:
Mar 26, 2013

MathJax-LaTeX < 1.2 - Cross-Site Request Forgery

high

The MathJax LaTeX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.2. This is due to missing or incorrect nonce validation on the mathjax_plugin_options function. This may make it possible for unauthenticated attackers to arbitrarily change plugin settings via a forged request grant...

CVSS:
8.8
Affected:
up to 1.2
Fixed in:
1.2
Disclosed:
Mar 25, 2013

MathJax-LaTeX [mathjax-latex] < 1.2

unknown

The MathJax LaTeX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.2. This is due to missing or incorrect nonce validation on the mathjax_plugin_options function. This may make it possible for unauthenticated attackers to arbitrarily change plugin settings via a forged request grant...

Affected:
up to 1.2
Fixed in:
1.2
Disclosed:
Mar 25, 2013

MathJax-LaTeX [mathjax-latex] < 1.2

unknown

The MathJax-LaTeX WordPress plugin was affected by a Setting Manipulation CSRF security vulnerability.

Affected:
up to 1.2
Fixed in:
1.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database