Junglewise Threat Intelligence

CVE-2025-13533: CSS & JavaScript Toolbox stored XSS in Assignment Engine

CVE-2025-13533 · Severity: medium · CVSS 4.4 · Published 2026-09-18

Executive brief

The CSS & JavaScript Toolbox is a popular WordPress plugin that allows administrators to inject custom CSS and JavaScript into websites. The plugin contains a stored cross-site scripting (XSS) vulnerability in its Assignment Engine that permits authenticated administrators to inject malicious scripts into pages. When other administrators access the plugin's configuration screen, the injected scripts execute, potentially compromising administrator accounts and the entire WordPress installation.

Technical details

The vulnerability is a Stored Cross-Site Scripting (XSS) flaw in the Assignment Engine component of the CSS & JavaScript Toolbox plugin (versions up to 12.0.6). The vulnerability stems from insufficient input sanitization and output escaping on assignment data fields, including Expressions, URLs, and Advanced assignment data. An authenticated attacker with Administrator-level access can inject arbitrary JavaScript payloads into these assignment fields, which are then stored in the database. When any administrator opens the CJT block edit screen in the WordPress admin dashboard, the unsanitized payloads are rendered directly into the admin interface and executed in the browser. The attack requires Administrator privileges to inject the payload, but the malicious scripts execute with the privileges of any administrator who accesses the affected configuration screen.

Affected products

  • CSS & JavaScript Toolbox CSS & JavaScript Toolbox up to and including 12.0.6

Timeline

  • 2025-09-18: disclosed: Vulnerability publicly disclosed via NVD
  • 2025-11-20: exploited: Proof of concept published on GitHub Gist

References