WordPress · Css & Javascript Toolbox · CVE-2025-13533
**Name of the Vulnerable Software and Affected Versions**
CSS & JavaScript Toolbox versions prior to 12.0.7
**Description**
The plugin is subject to Stored Cross-Site Scripting (XSS), a flaw where malicious scripts are permanently stored on the target server. The issue exists within the Assignment Engine fields due to insufficient input sanitization and output escaping on data fields including `Expressions`, `URLs`, and `Advanced assignment data`. Authenticated attackers with Administrator-level access or higher can inject arbitrary web scripts that execute when a user accesses the CJT block edit screen in the admin dashboard.
**Recommendations**
Update the plugin to version 12.0.7 or later.
Restrict access to the Assignment Engine fields for `Expressions`, `URLs`, and `Advanced assignment data` to minimize the risk of exploitation.