Say the site has an XSS vector, but the site owner has taken the reasonable precaution of putting in a Content-Security-Policy that would disallow XSS from injecting <script> tags; this would seem to poke a hole in that protection. (Unless, perhaps, similar protections where applied to CSS, but I don't think most people expect CSS to do this; the attack outline in the article was novel (and clever) to me.)