Medium severity6.1NVD Advisory· Published Sep 19, 2019· Updated Jun 17, 2026
CVE-2019-16525
CVE-2019-16525
Description
An XSS issue was discovered in the checklist plugin before 1.1.9 for WordPress. The fill parameter is not correctly filtered in the checklist-icon.php file, and it is possible to inject JavaScript code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- WordPress/checklist plugindescription
Patches
Vulnerability mechanics
References
4- plugins.trac.wordpress.org/changeset/2155029/nvdPatchThird Party Advisory
- packetstormsecurity.com/files/154436/WordPress-Checklist-1.1.5-Cross-Site-Scripting.htmlnvdExploitThird Party AdvisoryVDB Entry
- wpvulndb.com/vulnerabilities/9877nvdThird Party Advisory
- wordpress.org/plugins/checklist/nvdProductRelease Notes
News mentions
0No linked articles in our index yet.