What CVE-2026-15273 Establishes
The disclosure is precise about the mechanics. In all versions of Automatic.css 4.0.0, the attacker-controlled REQUEST_URI is handled with insufficient input sanitization and output escaping, and the plugin stores the resulting value. No authentication is required — any visitor who sends a crafted request can plant an arbitrary web script. That script executes whenever an administrator accesses the plugin's Activity Log settings page, which places attacker-chosen code inside a privileged browser session. Automatic.css 4.0.1 is the release the vendor identifies as fixed. No code review is needed to understand the exposure: any site running 4.0.0 persists unsanitized URL input and renders it to administrators.
BitFire WAF Blocks the Poisoned Request at the Door
This attack begins with a single crafted request URL, and that is exactly where BitFire stops it. The BitFire FREE Web Application Firewall evaluates what a request contains before WordPress or any plugin processes it, inspecting URLs and query strings for cross-site scripting payloads. A request whose URI carries injected script markup is detected and blocked outright, so the poisoned REQUEST_URI never reaches Automatic.css 4.0.0's storage path and never reaches an administrator's browser. Because the WAF targets payload content rather than a CVE-specific signature, this protection applies to the exploit chain from the first request — even before you update the plugin — and it keeps guarding against similar script-injection attempts across your entire site.
If Your Site Was Affected, Investigate for Persistence.
Update to Automatic.css 4.0.1 immediately — it is the release the vendor identifies as fixed. Patching closes the vulnerable path, but it cannot undo exploitation that already happened. If an attacker planted a script while your site ran 4.0.0, that code executed with an administrator's privileges, precisely the level of access attackers use to establish persistence. Run BitFire Threat Hunter, a thorough post-compromise investigation that checks for backdoor administrator accounts, hidden database triggers, WordPress and server cron persistence, suspicious database content, long-running PHP processes, and droppers that can restore malware or reinfect the site. Remove everything it finds, rotate administrator credentials, and remember that a site with no visible malicious file is not automatically a clean site.
Conclusion: Patch Now, Then Defend Every Request
CVE-2026-15273 turns an ordinary request URI into a delivery channel for scripts that run in your administrators' browsers. The response is layered: enable BitFire FREE's Web Application Firewall so malicious script payloads are blocked at the request line before any plugin can store them, update Automatic.css to 4.0.1 today, and run BitFire Threat Hunter on any site that ever ran an affected version. Do all three — prevention, patching, and investigation — and a poisoned URL dies at your front door instead of inside your admin panel.