PT-2026-68019 · WordPress · Super Progressive Web Apps
CVSS v3.1
4.4
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Super Progressive Web Apps versions prior to 2.2.44
Description
Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping. The
superpwa settings[offline message txt] setting is stored without sanitization and passed to the frontend via wp localize script() without escaping. The value is then rendered using innerHTML in the JavaScript snackbar component. This allows authenticated attackers with Administrator-level access and above to inject arbitrary web scripts that execute when a user triggers the offline snackbar.Recommendations
Update Super Progressive Web Apps to version 2.2.44 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Super Progressive Web Apps