Vulnerabilities and security researches forsuper-progressive-web-apps super-progressive-web-apps
Direction: ascendingJun 07, 2024
Super Progressive Web Apps # d322aac99803486c4b5122c784b27134ce018b2e
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 29, 2021
- Research Description
- Super Progressive Web Apps [super-progressive-web-apps] < 2.1.13 WordPress Super Progressive Web Apps plugin <= 2.1.12 - Authenticated Arbitrary File Upload vulnerability leading to Remote Code Execution (RCE) Authenticated Arbitrary File Upload vulnerability leading to Remote Code Execution (RCE) discovered by WPScan Team in WordPress Super Progressive Web Apps plugin (versions <= 2.1.12).
- Affected versions
-
max 2.1.13.
- Status
-
vulnerable
Jun 10, 2024
Super Progressive Web Apps # CVE-2023-48277
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 09, 2024
- Research Description
- Missing Authorization vulnerability in SuperPWA Super Progressive Web Apps super-progressive-web-apps allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Super Progressive Web Apps: from n/a through <= 2.2.21.
- Affected versions
-
max 2.2.22.
- Status
-
vulnerable
Jun 16, 2026
Super Progressive Web Apps # fd1f0cee-44e7-4847-a53d-e54844399fd1
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- Super Progressive Web Apps [super-progressive-web-apps] < 2.1.13 Super Progressive Web Apps < 2.1.13 - Authenticated (High Privileged) Arbitrary File Upload to RCE When the Apple Touch Icons & Splash Screen add-on is active, its superpwa_splashscreen_uploader AJAX action, did not properly check for authorisation and the content of the uploaded archive file. This allows high privilege users (admin+) to upload an archive with a PHP file, leading to RCE. v2.1.12 attempted to fix the issue by deleting potential malicious files, after extracting the archive, but was checking the wrong folder. And even if the correct folder was checked, a race condition could have been used to exploit the issue
- Affected versions
-
max 2.1.13.
- Status
-
vulnerable
Super Progressive Web Apps # 4fd989ae-db35-40fa-ba61-b2d4fbb3994d
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- Super Progressive Web Apps [super-progressive-web-apps] < 2.1.12 Super Progressive Web Apps < 2.1.12 - Authenticated (Low Privileged) Arbitrary File Upload to RCE When the Apple Touch Icons & Splash Screen add-on is active, its superpwa_splashscreen_uploader AJAX action, does not properly check for CSRF, authorisation and the content of the uploaded archive file. This allows attackers to upload an archive with a PHP file, leading to RCE by either using a low privilege account (subscriber+) or a CSRF attack on any logged in user. v2.1.11 fixed the CSRF check, only. v2.1.12 added capability check.
- Affected versions
-
max 2.1.12.
- Status
-
vulnerable
Super Progressive Web Apps # 408a6cd0d752a50b38c5f6f8dcb126aa9bceaaec
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 29, 2022
- Research Description
- Super Progressive Web Apps [super-progressive-web-apps] < 2.2.9 Super Progressive Web Apps <= 2.2.8 - Missing Authorization The Super Progressive Web Apps plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the superpwa_send_feedback function in versions up to, and including, 2.2.8. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to submit feedback to the plugin developers.
- Affected versions
-
max 2.2.9.
- Status
-
vulnerable
Aug 06, 2026
Super Progressive Web Apps # CVE-2026-5108
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 05, 2026
- Research Description
- The Super Progressive Web Apps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `superpwa_settings[offline_message_txt]` setting in all versions up to, and including, 2.2.43. This is due to insufficient input sanitization and output escaping. The offline message value is stored without sanitization, passed to the frontend via `wp_localize_script()` without escaping, and rendered using `innerHTML` in the JavaScript snackbar component. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user triggers the offline snackbar.
- Affected versions
-
max 2.2.44.
- Status
-
vulnerable