CVE-2019-16525: Checklist

Medium severity, CVSS 6.1. EPSS: 5.5% chance of exploitation in the next 30 days.

An XSS issue was discovered in the checklist plugin before 1.1.9 for WordPress. The fill parameter is not correctly filtered in the checklist-icon.php file, and it is possible to inject JavaScript code.

Affected products

  • Checklist Checklist: before 1.1.9 (fixed in 1.1.9)

Published 2019-09-19. Last modified 2026-06-17.