Super Progressive Web Apps, 408a6cd0d752a50b38c5f6f8dcb126aa9bceaaec
- CVE, Research URL
- Home page URL
- Application
- Published on
- Nov 29, 2022
- Research Description
- Super Progressive Web Apps [super-progressive-web-apps] < 2.2.9 Super Progressive Web Apps <= 2.2.8 - Missing Authorization The Super Progressive Web Apps plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the superpwa_send_feedback function in versions up to, and including, 2.2.8. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to submit feedback to the plugin developers.
- Affected versions
-
max 2.2.9.
- Status
-
vulnerable