cleantalk
Vulnerabilities and Security Researches

Super Progressive Web Apps, 408a6cd0d752a50b38c5f6f8dcb126aa9bceaaec

Published on
Nov 29, 2022
Research Description
Super Progressive Web Apps [super-progressive-web-apps] < 2.2.9 Super Progressive Web Apps <= 2.2.8 - Missing Authorization The Super Progressive Web Apps plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the superpwa_send_feedback function in versions up to, and including, 2.2.8. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to submit feedback to the plugin developers.
Affected versions
max 2.2.9.
Status
vulnerable