A vulnerability has been found in CSS & JavaScript Toolbox Plugin up to 12.0.5 on WordPress and classified as problematic. Affected by this issue is some unknown functionality of the component Setting Handler. Performing manipulation results in cross site scripting.

This vulnerability is reported as CVE-2025-11928. The attack is possible to be carried out remotely. No exploit exists.