Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Howard Website LLMs.txt website-llms-txt allows Reflected XSS.This issue affects Website LLMs.txt: from n/a through <= 8.2.6.
Published: 2026-03-19
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (XSS)
Action: Update
AI Analysis

Impact

The CVE identifies an Improper Neutralization of Input During Web Page Generation flaw that allows reflected XSS in the Website LLMs.txt plugin. This means user‑supplied data can be echoed back into a page without proper sanitization, exposing the site to arbitrary script execution in a visitor’s browser. Typical consequences of such a flaw could include hijacking user sessions or stealing credentials, but the CVE description does not explicitly state these outcomes, so the impact is inferred from the nature of XSS.

Affected Systems

WordPress sites operating the Website LLMs.txt plugin by Ryan Howard are affected. Versions from the earliest releases through 8.2.6 are vulnerable; any site running one of those releases requires attention.

Risk and Exploitability

The vulnerability can be triggered remotely by supplying crafted input that the plugin reflects back, likely via URLs or form fields, and it requires no authentication. The EPSS score is below 1 %, indicating a low reported likelihood of exploitation, and the flaw is not listed in CISA’s KEV catalog. Despite the low exploitation probability, a reflected XSS flaw can be weaponized through social engineering or malicious links, so guard against the potential for script injection should the plugin remain unpatched.

Generated by OpenCVE AI on April 2, 2026 at 05:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Website LLMs.txt plugin to the latest available version from the developer’s site, which removes the reflected XSS flaw. If a patch is not immediately available, consider temporarily disabling the plugin or blocking its input mechanisms until an official fix is released.
  • After updating, verify that all site functionality remains intact and that no older or cached versions of the plugin persist in the environment.

Generated by OpenCVE AI on April 2, 2026 at 05:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Howard Website LLMs.Txt allows Reflected XSS.This issue affects Website LLMs.Txt: from n/a through 8.2.6. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Howard Website LLMs.txt website-llms-txt allows Reflected XSS.This issue affects Website LLMs.txt: from n/a through <= 8.2.6.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 20 Mar 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Ryan Howard
Ryan Howard website Llms.txt
Wordpress
Wordpress wordpress
Vendors & Products Ryan Howard
Ryan Howard website Llms.txt
Wordpress
Wordpress wordpress

Thu, 19 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 19 Mar 2026 09:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Howard Website LLMs.Txt allows Reflected XSS.This issue affects Website LLMs.Txt: from n/a through 8.2.6.
Title WordPress Website LLMs.txt plugin <= 8.2.6 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Ryan Howard Website Llms.txt
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-23T14:14:10.331Z

Reserved: 2026-02-17T13:23:42.768Z

Link: CVE-2026-27068

cve-icon Vulnrichment

Updated: 2026-03-19T13:50:02.766Z

cve-icon NVD

Status : Deferred

Published: 2026-03-19T09:16:18.157

Modified: 2026-04-23T15:37:15.803

Link: CVE-2026-27068

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-02T07:59:48Z

Weaknesses