Executive brief
The AppMySite WordPress plugin, used to build mobile apps without coding, contains a stored cross-site scripting flaw in its license key handler. Any authenticated WordPress user with subscriber-level access or above can inject malicious scripts that persist in the database and execute when other users view affected pages, potentially leading to account compromise or data theft.
Technical details
The save_ams_license_key AJAX handler in the plugin performs insufficient input sanitization and output escaping, allowing authenticated attackers to inject arbitrary JavaScript. The vulnerability is enabled by the absence of capability checks and nonce verification, meaning any subscriber-level user can invoke the handler. Exploitation requires authentication but no user interaction beyond accessing an injected page.
Affected products
- AppMySite WordPress & WooCommerce Mobile App Builder up to and including 3.15.3
Timeline
- 2026-09-19: disclosed