## https://sploitus.com/exploit?id=WPEX-ID:449E4DA8-BEAE-4FF6-9DDC-0E17781C0391 1. Add a checklist and for an item, enter `<script>alert(999)</script>` 2. Display the checklist via shortcode and view on the frontend to see the XSS