Super Progressive Web Apps
Super Progressive Web Apps converts WordPress websites into progressive web applications with app-like features.
Super Progressive Web Apps (super-progressive-web-apps) is a WordPress plugin with 2 published CVE records in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 4.4.
super-progressive-web-appsCVE-2026-5108: Super Progressive Web Apps offline message reaches innerHTML as stored XSS
Super Progressive Web Apps through 2.2.43 stores superpwa_settings[offline_message_txt] without sanitization, exports the value to frontend JavaScript through wp_localize_script(), and assigns it to innerHTML in the snackbar component. An Administrator can store JavaScript that executes for users who trigger the offline snackbar. This 4.4-scored record received deeper review because the persistent frontend payload can reach site visitors, including another administrator. The CNA does not disclose the settings action or PHP save handler.
| Safe version |
|
||
|---|---|---|---|
| Aug 05, 2026 |
CVE-2026-5108
Super Progressive Web Apps offline message reaches innerHTML as stored XSS
Super Progressive Web Apps through 2.2.43 stores superpwa_settings[offline_message_txt] without sanitization, exports the value to frontend JavaScript through wp_localize_script(), and assigns it to innerHTML in the snackbar component. An Administrator can store JavaScript that executes for users who trigger the offline snackbar. This 4.4-scored record received deeper review because the persistent frontend payload can reach site visitors, including another administrator. The CNA does not disclose the settings action or PHP save handler.
|
> 2.2.43 |
CVE4.4
NVDPending
|
| Dec 09, 2024 |
CVE-2023-48277
Super Progressive Web Apps: A security weakness
Super Progressive Web Apps is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.3
NVDPending
|