Input validation vulnerability in CSS & JavaScript Toolbox 11.7

The WordPress CSS & JavaScript Toolbox plugin is vulnerable to a type of cyber attack called Stored Cross-Site Scripting. This type of attack can be used by someone with an account on the website who has at least the Contributor-level permission. It allows them to inject malicious scripts into pages which will be executed when any user visits the page. This affects all versions of the plugin up to 11.7, due to the fact that it does not properly sanitize and protect user-provided input.

Detected in:

CSS & JavaScript Toolbox fixed vulnerable versions: >= * <= 11.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.