Record summary

CVE-2019-16525 has a selected CVSS score of 6.1 (medium); EIP currently links 1 curated repository PoC and 1 Nuclei template.

Description

An XSS issue was discovered in the checklist plugin before 1.1.9 for WordPress. The fill parameter is not correctly filtered in the checklist-icon.php file, and it is possible to inject JavaScript code.

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
1
Nuclei templates
1

Proofs of concept

1

Curated repository PoCs

GitHubCVE-2019-16525Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 290 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Checklist <1.1.9 - Cross-Site ScriptingCVSS 6.1

WordPress Checklist plugin before 1.1.9 contains a cross-site scripting vulnerability. The fill parameter is not correctly filtered in the checklist-icon.php file.

Impact

Allows attackers to inject malicious scripts into web pages viewed by users, leading to potential data theft or unauthorized actions.

Remediation

Update to the latest version of the WordPress Checklist plugin (1.1.9 or higher) to mitigate this vulnerability.

WeaknessesCWE-79
Authorsdaffainfo
Template tagscvecve2019xsswp-pluginpacketstormwordpresschecklistvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:checklist:checklist:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

5