WM JqMath Security & Risk Analysis

wordpress.org/plugins/wm-jqmath

Create math formulas on your posts and pages using jqMath from MathScribe

20 active installs v1.3 PHP + WP 3.3+ Updated Aug 5, 2015
jqmathwebmindwm
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEApr 14, 2026
Safety Verdict

Is WM JqMath Safe to Use in 2026?

Use With Caution

Score 63/100

WM JqMath has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Apr 14, 2026Updated 10yr ago
Risk Assessment

The wm-jqmath plugin v1.3 exhibits a strong security posture based on the provided static analysis and vulnerability history. The code appears to follow best practices by not utilizing dangerous functions, all SQL queries are prepared, and all outputs are properly escaped. The absence of file operations and external HTTP requests further reduces the attack surface. Notably, there are no recorded vulnerabilities (CVEs) for this plugin, indicating a history of stable and secure development or a lack of prior discovery. The limited attack surface, consisting solely of two shortcodes, is also a positive sign. However, the complete absence of nonce checks and capability checks on these shortcodes represents a potential oversight. While no vulnerabilities are immediately apparent from the static analysis due to the lack of complex flows, an attacker could potentially exploit these entry points if they were to lead to any sensitive operations or unintended behavior that isn't properly secured.

Key Concerns

  • Shortcodes lack nonce checks
  • Shortcodes lack capability checks
Vulnerabilities
1

WM JqMath Security Vulnerabilities

CVEs by Year

1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-3998medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WM JqMath <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Attribute

Apr 14, 2026Unpatched
Version History

WM JqMath Release Timeline

v1.3Current1 CVE
v1.21 CVE
v1.11 CVE
v1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

WM JqMath Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

WM JqMath Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[enable_jqmath] wm_jqmath.php:38
[jqmath] wm_jqmath.php:39
Maintenance & Trust

WM JqMath Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedAug 5, 2015
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

WM JqMath Developer Profile

webmind.pt

1 plugin · 20 total installs

68
trust score
Avg Security Score
63/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WM JqMath

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wm-jqmath/css/jqmath-0.4.3.css/wp-content/plugins/wm-jqmath/js/jqmath-etc-0.4.3.min.js
Script Paths
/wp-content/plugins/wm-jqmath/js/jqmath-etc-0.4.3.min.js
Version Parameters
wm-jqmath/css/jqmath-0.4.3.css?ver=wm-jqmath/js/jqmath-etc-0.4.3.min.js?ver=

HTML / DOM Fingerprints

Data Attributes
style
Shortcode Output
<span
FAQ

Frequently Asked Questions about WM JqMath