Impact
The AppMySite plugin is vulnerable to stored XSS via the save_ams_license_key AJAX handler. The handler accepts data without sanitization and lacks capability checks, allowing an authenticated user with Subscriber privileges to inject arbitrary scripts into the license key field. When a user later views a page that renders this stored value, the malicious JavaScript executes in that user’s browser.
Affected Systems
The vulnerability affects the AppMySite – WordPress & WooCommerce Mobile App Builder plugin for WordPress, all releases up to and including 3.15.3.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate risk, and the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, meaning no known widespread exploited incidents. Attackers need only authenticated access at Subscriber level or higher, and then can exploit the AJAX endpoint without further credentials. Because the payload is stored, it affects all subsequent users who view the affected pages, posing a cross‑site scripting risk to the site’s front‑end users.
OpenCVE Enrichment