CVE-2026-6711: The Website LLMs.txt plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 8.2.6. This is due to the use of filter_input...

Added to the CISA Known Exploited Vulnerabilities catalog on 21 Apr 2026. Vendor: AI/ML. Product: LLM. CVSS score: 6.1.

The Website LLMs.txt plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 8.2.6. This is due to the use of filter_input() without a sanitization filter and insufficient output escaping. This makes it possible for unauth...

Required action: Review and patch if applicable to your AI infrastructure.