PT-2026-95309 · WordPress · Css & Javascript Toolbox

·

CVE-2025-13533

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

4.4

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CSS & JavaScript Toolbox versions prior to 12.0.7
Description The plugin is subject to Stored Cross-Site Scripting (XSS), a flaw where malicious scripts are permanently stored on the target server. The issue exists within the Assignment Engine fields due to insufficient input sanitization and output escaping on data fields including Expressions, URLs, and Advanced assignment data. Authenticated attackers with Administrator-level access or higher can inject arbitrary web scripts that execute when a user accesses the CJT block edit screen in the admin dashboard.
Recommendations Update the plugin to version 12.0.7 or later. Restrict access to the Assignment Engine fields for Expressions, URLs, and Advanced assignment data to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-13533

Affected Products

Css & Javascript Toolbox