WordPress Checklist plugin before 1.1.9 contains a cross-site scripting vulnerability. The fill parameter is not correctly filtered in the checklist-icon.php file.
View the template here CVE-2019-16525.yaml
References:
https://wpvulndb.com/vulnerabilities/9877