← WordPress Vulnerabilities
WordPress security by component

Super Progressive Web Apps

Super Progressive Web Apps converts WordPress websites into progressive web applications with app-like features.

Super Progressive Web Apps (super-progressive-web-apps) is a WordPress plugin with 2 published CVE records in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 4.4.

Plugin slug: super-progressive-web-apps

CVE-2026-5108: Super Progressive Web Apps offline message reaches innerHTML as stored XSS

Super Progressive Web Apps through 2.2.43 stores superpwa_settings[offline_message_txt] without sanitization, exports the value to frontend JavaScript through wp_localize_script(), and assigns it to innerHTML in the snackbar component. An Administrator can store JavaScript that executes for users who trigger the offline snackbar. This 4.4-scored record received deeper review because the persistent frontend payload can reach site visitors, including another administrator. The CNA does not disclose the settings action or PHP save handler.

PublishedAug 05, 2026
Known safe version> 2.2.43
Published vulnerabilities for super-progressive-web-apps
Safe version
Aug 05, 2026 CVE-2026-5108
Super Progressive Web Apps offline message reaches innerHTML as stored XSS
Super Progressive Web Apps through 2.2.43 stores superpwa_settings[offline_message_txt] without sanitization, exports the value to frontend JavaScript through wp_localize_script(), and assigns it to innerHTML in the snackbar component. An Administrator can store JavaScript that executes for users who trigger the offline snackbar. This 4.4-scored record received deeper review because the persistent frontend payload can reach site visitors, including another administrator. The CNA does not disclose the settings action or PHP save handler.
> 2.2.43
CVE4.4
NVDPending
Dec 09, 2024 CVE-2023-48277
Super Progressive Web Apps: A security weakness
Super Progressive Web Apps is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE4.3
NVDPending