VYPR

Automatic.css

by WordPress

CVEs (1)

  • CVE-2026-15273MedSep 26, 2026
    risk 0.42cvss 6.4epss —

    The Automatic.css plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI in all version 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that will…