CVE-2019-16525
18Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 5.5%
exploitation probability
5.5%top 8% of all CVEs
observed exploitation
nono source reports it
An XSS issue was discovered in the checklist plugin before 1.1.9 for WordPress. The fill parameter is not correctly filtered in the checklist-icon.php file, and it is possible to inject JavaScript code.
Affected products
n/a · n/a