Stored Cross-Site Scripting Vulnerability in AppMySite WordPress Plugin
CVE-2026-13770
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 September 2026
What is CVE-2026-13770?
The AppMySite plugin for WordPress and WooCommerce is susceptible to a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping mechanisms. Authenticated users with Subscriber-level access or higher can exploit this vulnerability through the 'save_ams_license_key' AJAX handler, which lacks critical capability checks and nonce verification. Attackers may inject malicious scripts that execute whenever users access pages containing the injected code, potentially compromising the integrity of the affected site and its users.
Affected Version(s)
AppMySite β WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker) 0 <= 3.15.3