---
id: CVE-2025-13533
title: >-
  The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored
  Cross-Site Scripting in all versions up to, and including, 12.0.6 via the
  Assignment Engine fields
summary: >-
  The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored
  Cross-Site Scripting in all versions up to, and including, 12.0.6 via the
  Assignment Engine fields. This is due to insufficient input sanitization and
  output escap…
severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: wipeoutmedia
product: CSS & JavaScript Toolbox
affected:
  - css_javascript_toolbox <= 12.0.6
published: '2026-09-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T15:17:04.087'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13533'
references:
  - url: 'https://gist.github.com/e578d548291225c116a5827ad205a9e9'
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/css-javascript-toolbox/tags/12.0.6/controllers/block-ajax.php#L184
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/css-javascript-toolbox/trunk/controllers/block-ajax.php#L184
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?reponame=&old=3667323%40css-javascript-toolbox&new=3667323%40css-javascript-toolbox
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/98ef6eeb-9fd5-4ecc-a75a-e17884b9d41a?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-18T14:37:07.364695Z'
epss: 0.00195
epssPercentile: 0.08144
ingestedAt: '2026-09-18T08:38:04.111Z'
---

## Overview

The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 12.0.6 via the Assignment Engine fields. This is due to insufficient input sanitization and output escaping on assignment data fields including Expressions, URLs, and Advanced assignment data. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the CJT block edit screen in the admin dashboard.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
