← back
CVE-2019-16525

CVE-2019-16525

18Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 5.5%
exploitation probability
5.5%top 8% of all CVEs
observed exploitation
nono source reports it
An XSS issue was discovered in the checklist plugin before 1.1.9 for WordPress. The fill parameter is not correctly filtered in the checklist-icon.php file, and it is possible to inject JavaScript code.
Affected products
n/a · n/a