WordPress Checklist plugin before 1.1.9 contains a cross-site scripting vulnerability. The fill parameter is not correctly filtered in the checklist-icon.php file.
id: CVE-2019-16525
info:
name: WordPress Checklist <1.1.9 - Cross-Site Scripting
author: daffai
...