The Website LLMs.txt plugin for WordPress is vulnerable to Cross-Site Scripting attacks due to insufficient input sanitization and output escaping.
Claims
The Website LLMs.txt plugin for WordPress is vulnerable to Cross-Site Scripting attacks due to insufficient input sanitization and output escaping.
Parent: CybersecurityEntity: WordPress pluginsSub-entity: Website LLMs.txt PluginImpact: negativeDate: Apr 21, 2026Target: The security of WordPress plugins
Source posts
๐จ EUVD-2026-24072
๐ Score: 4.4/10 (CVSS v3.1)
๐ฆ Product: Website LLMs.txt
๐ข Vendor: ryhowa
๐
Updated: 2026-04-21
๐ The Website LLMs.txt plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24072
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24071
๐ Score: 6.1/10 (CVSS v3.1)
๐ฆ Product: Website LLMs.txt
๐ข Vendor: ryhowa
๐
Updated: 2026-04-21
๐ The Website LLMs.txt plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 8.2.6. This is due to the use of filter_input() without a sanitization filter and insufficient out...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24071
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability