What CVE-2026-15273 Establishes
Automatic.css for WordPress is vulnerable to Stored Cross-Site Scripting in every 4.0.0 release. The plugin accepts the REQUEST_URI value with insufficient input sanitization and outputs it without proper escaping, so an unauthenticated attacker can plant arbitrary web scripts that the plugin stores. No credentials, session, or victim cooperation is required on the attacker's side beyond one crafted request. The stored script then executes whenever an administrator accesses the plugin's Activity Log settings page — attacker-chosen code running inside a privileged browser session. Version 4.0.1 is the release the vendor identifies as fixed.
BitFire FREE WAF: The Payload Is Blocked Before It Is Stored
This exploit lives or dies at the request layer, and that is exactly where BitFire inspects it. Before WordPress or Automatic.css processes anything, the BitFire WAF examines request URLs and query strings — and REQUEST_URI is the request URL itself. Its Cross-Site Scripting detection identifies malicious script payloads in inspected request data and blocks the request outright. The injection step of this chain is a documented exploit requirement, and BitFire removes it: nothing is stored, so nothing renders inside an administrator's browser. BitFire FREE delivers this WAF protection for eligible non-commercial sites; commercial sites require the appropriate commercial license.
If Your Site Was Affected, Investigate for Persistence
Patching to 4.0.1 closes the injection point, but it does nothing about a script that already executed in an administrator's browser. If Automatic.css 4.0.0 was installed while any administrator visited the Activity Log settings page, treat the site as potentially compromised and investigate immediately. BitFire Threat Hunter performs a thorough post-compromise investigation: it hunts backdoor administrator accounts, hidden database triggers, WordPress and server cron persistence, must-use plugins and startup-chain modifications, long-running PHP processes, and the droppers that can restore malware after cleanup. Remove every persistence mechanism it finds and rotate administrator credentials. A site that looks clean on the surface is not proven clean — investigate before you trust it.
Patch Today, Defend in Depth
Update Automatic.css to 4.0.1 today and make BitFire part of the same response. BitFire's WAF stands between unauthenticated attackers and this injection point, and BitFire Threat Hunter is ready if the plugin ran exposed before protection was in place. There is no reason to keep running an unauthenticated, admin-targeted script injection when a fixed release is available. Install or enable BitFire, patch to 4.0.1, and run a Threat Hunter investigation on any site that hosted version 4.0.0 — then let this CVE end as a non-event.