LaTeX2HTML
LaTeX2HTML has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2024; all 2 are fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10. 2024 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for LaTeX2HTML has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. LaTeX2HTML is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2024-11688LaTeX2HTML <= 2.5.5 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records

LaTeX2HTML
Author
Van Abel
LaTeX2HTML makes you write blog like in LaTeX doc. You can just copy and paste to create a new post in WP from your tex source file, then it will looks like amsart document style. It support a lot of raw latex command including theorem like environment and BibTeX style citation. Main Functions Enable MathJax to render math formula. Translate raw LaTeX (almost all the command of amsart) to HTML+CSS markup. Almost every thing is customizable, but also works perfect by default. e.g., support \newcommand License Good news, this plugin is free for everyone! Since it’s released under the GPL2, you can use it free of charge on your personal or commercial blog.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C