cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forsuper-progressive-web-apps super-progressive-web-apps

Direction: ascending
Jun 07, 2024

Super Progressive Web Apps # d322aac99803486c4b5122c784b27134ce018b2e

Date
Jun 29, 2021
Research Description
Super Progressive Web Apps [super-progressive-web-apps] < 2.1.13 WordPress Super Progressive Web Apps plugin <= 2.1.12 - Authenticated Arbitrary File Upload vulnerability leading to Remote Code Execution (RCE) Authenticated Arbitrary File Upload vulnerability leading to Remote Code Execution (RCE) discovered by WPScan Team in WordPress Super Progressive Web Apps plugin (versions <= 2.1.12).
Affected versions
max 2.1.13.
Status
vulnerable
Jun 10, 2024

Super Progressive Web Apps # CVE-2023-48277

CVE, Research URL

CVE-2023-48277

Date
Dec 09, 2024
Research Description
Missing Authorization vulnerability in SuperPWA Super Progressive Web Apps super-progressive-web-apps allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Super Progressive Web Apps: from n/a through <= 2.2.21.
Affected versions
max 2.2.22.
Status
vulnerable
Jun 16, 2026

Super Progressive Web Apps # fd1f0cee-44e7-4847-a53d-e54844399fd1

Date
-
Research Description
Super Progressive Web Apps [super-progressive-web-apps] < 2.1.13 Super Progressive Web Apps &lt; 2.1.13 - Authenticated (High Privileged) Arbitrary File Upload to RCE When the Apple Touch Icons &amp; Splash Screen add-on is active, its superpwa_splashscreen_uploader AJAX action, did not properly check for authorisation and the content of the uploaded archive file. This allows high privilege users (admin+) to upload an archive with a PHP file, leading to RCE. v2.1.12 attempted to fix the issue by deleting potential malicious files, after extracting the archive, but was checking the wrong folder. And even if the correct folder was checked, a race condition could have been used to exploit the issue
Affected versions
max 2.1.13.
Status
vulnerable

Super Progressive Web Apps # 4fd989ae-db35-40fa-ba61-b2d4fbb3994d

Date
-
Research Description
Super Progressive Web Apps [super-progressive-web-apps] < 2.1.12 Super Progressive Web Apps &lt; 2.1.12 - Authenticated (Low Privileged) Arbitrary File Upload to RCE When the Apple Touch Icons &amp; Splash Screen add-on is active, its superpwa_splashscreen_uploader AJAX action, does not properly check for CSRF, authorisation and the content of the uploaded archive file. This allows attackers to upload an archive with a PHP file, leading to RCE by either using a low privilege account (subscriber+) or a CSRF attack on any logged in user. v2.1.11 fixed the CSRF check, only. v2.1.12 added capability check.
Affected versions
max 2.1.12.
Status
vulnerable

Super Progressive Web Apps # 408a6cd0d752a50b38c5f6f8dcb126aa9bceaaec

Date
Nov 29, 2022
Research Description
Super Progressive Web Apps [super-progressive-web-apps] < 2.2.9 Super Progressive Web Apps <= 2.2.8 - Missing Authorization The Super Progressive Web Apps plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the superpwa_send_feedback function in versions up to, and including, 2.2.8. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to submit feedback to the plugin developers.
Affected versions
max 2.2.9.
Status
vulnerable
Aug 06, 2026

Super Progressive Web Apps # CVE-2026-5108

CVE, Research URL

CVE-2026-5108

Date
Aug 05, 2026
Research Description
The Super Progressive Web Apps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `superpwa_settings[offline_message_txt]` setting in all versions up to, and including, 2.2.43. This is due to insufficient input sanitization and output escaping. The offline message value is stored without sanitization, passed to the frontend via `wp_localize_script()` without escaping, and rendered using `innerHTML` in the JavaScript snackbar component. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user triggers the offline snackbar.
Affected versions
max 2.2.44.
Status
vulnerable