Impact
The CSS & JavaScript Toolbox plugin for WordPress is susceptible to a stored cross‑site scripting vulnerability through its Assignment Engine fields. The flaw, categorized as CWE‑79, arises from insufficient sanitization and escaping of input data such as expressions, URLs, and advanced assignment data. An attacker with Administrator or higher privileges can embed arbitrary JavaScript that is persisted and will execute whenever an administrator opens the CJT block edit screen in the admin dashboard. The result is that the injected script runs in the context of the administrator’s browser session on that screen. Based on the description, it is inferred that such scripts could potentially compromise administrator accounts or allow malicious manipulation of site content, although these outcomes are not directly confirmed in the CVE text.
Affected Systems
The flaw affects wipeoutmedia’s CSS & JavaScript Toolbox plugin for WordPress in all releases up to and including 12.0.6. WordPress sites that have installed this plugin, regardless of other plugins or themes, are impacted, while newer releases are not.
Risk and Exploitability
The CVSS score of 4.4 indicates low severity, and the EPSS score of < 1% reflects a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a pre‑existing authenticated session with Administrator or higher privileges; the stored script only executes when such a user visits the block editing page. Consequently, the impact is limited to the administrative user base, but the ability to run arbitrary code in that context can facilitate further attacks or content tampering if the administrator is compromised.
OpenCVE Enrichment