Stored Cross-Site Scripting Vulnerability in CSS & JavaScript Toolbox Plugin for WordPress
CVE-2025-11928

4.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 November 2025

What is CVE-2025-11928?

The CSS & JavaScript Toolbox plugin for WordPress has a vulnerability that allows authenticated attackers with administrator-level permissions to perform Stored Cross-Site Scripting through the admin settings. This issue arises from inadequate input sanitization and output escaping, making it feasible to inject malicious scripts into pages. As a result, when users access these pages, the injected scripts are executed in their browsers. The vulnerability is confined to multi-site installations and those where the 'unfiltered_html' capability has been disabled, exposing users to potential attacks.

Affected Version(s)

CSS & JavaScript Toolbox * <= 12.0.5

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chairat Toraya
.
CVE-2025-11928 : Stored Cross-Site Scripting Vulnerability in CSS & JavaScript Toolbox Plugin for WordPress