Stored Cross-Site Scripting Vulnerability in CSS & JavaScript Toolbox Plugin for WordPress
CVE-2025-11928
4.4MEDIUM
What is CVE-2025-11928?
The CSS & JavaScript Toolbox plugin for WordPress has a vulnerability that allows authenticated attackers with administrator-level permissions to perform Stored Cross-Site Scripting through the admin settings. This issue arises from inadequate input sanitization and output escaping, making it feasible to inject malicious scripts into pages. As a result, when users access these pages, the injected scripts are executed in their browsers. The vulnerability is confined to multi-site installations and those where the 'unfiltered_html' capability has been disabled, exposing users to potential attacks.
Affected Version(s)
CSS & JavaScript Toolbox * <= 12.0.5