PT-2026-95309 · WordPress · Css & Javascript Toolbox
CVSS v3.1
4.4
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
CSS & JavaScript Toolbox versions prior to 12.0.7
Description
The plugin is subject to Stored Cross-Site Scripting (XSS), a flaw where malicious scripts are permanently stored on the target server. The issue exists within the Assignment Engine fields due to insufficient input sanitization and output escaping on data fields including
Expressions, URLs, and Advanced assignment data. Authenticated attackers with Administrator-level access or higher can inject arbitrary web scripts that execute when a user accesses the CJT block edit screen in the admin dashboard.Recommendations
Update the plugin to version 12.0.7 or later.
Restrict access to the Assignment Engine fields for
Expressions, URLs, and Advanced assignment data to minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Css & Javascript Toolbox