PWA plugin is bringing the power of the Progressive Web Apps to the WP & AMP to take the user experience to the next level.
Qué hace este plugin
- Slug:
pwa-for-wp
- Autor: Magazine3
- 20000+ instalaciones activas
- 92/100 calificación (229 reseñas en wordpress.org)
- 1568478 descargas totales
- En WordPress.org desde 2018-08-16
cachemanifestofflineprogressive web appspwa
Estado de mantenimiento
- Última actualización: 2026-07-14 2:12pm GMT
- Probado hasta WordPress: 7.0.2
- PHP máximo soportado (analizado): 8.4
Vulnerabilidades conocidas
3 CVEs conocidos registrados para PWA for WP - Progressive Web Apps Made Simple.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2024-47318
|
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.73 |
Falta de control de autorización |
Media
4,3
|
< 1.7.73
|
1.7.73 |
2024-09-25 |
—
|
|
CVE-2021-4354
|
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33 |
Carga de archivos sin restricción de tipo peligroso |
Alta
8,8
|
< 1.7.33
|
1.7.33 |
2023-06-07 |
—
|
|
CVE-2021-4366
|
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33 |
Falta de control de autorización |
Media
4,3
|
< 1.7.33
|
1.7.33 |
2023-06-07 |
—
|
|
—
|
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33 |
— |
Desconocido
|
< 1.7.33
|
1.7.33 |
2021-07-01 |
—
|
|
—
|
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33 |
— |
Desconocido
|
< 1.7.33
|
1.7.33 |
2021-07-01 |
—
|
|
—
|
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33 |
— |
Desconocido
|
< 1.7.33
|
1.7.33 |
2021-07-01 |
—
|
|
—
|
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.0.9 |
— |
Desconocido
|
< 1.0.9
|
1.0.9 |
2019-03-25 |
—
|
|
—
|
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.72 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
4,8
|
< 1.7.72
|
1.7.72 |
0000-00-00 |
—
|
CVE-2024-47318
The PWA for WP & AMP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.7.72. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2021-4354
The PWA for WP & AMP for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pwaforwp_splashscreen_uploader function in versions up to, and including, 1.7.32. This makes it possible for authenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2021-4366
The PWA for WP & AMP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the pwaforwp_update_features_options function in versions up to, and including, 1.7.32. This makes it possible for authenticated attackers to change the otherwise restricted settings within the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33
Authenticated Arbitrary File Upload vulnerability discovered by Jerome Bruandet in WordPress PWA for WP & AMP plugin (versions <= 1.7.32).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33
The PWA for WP & AMP for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pwaforwp_splashscreen_uploader function in versions up to, and including, 1.7.32. This makes it possible for authenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33
The PWA for WP & AMP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the pwaforwp_update_features_options function in versions up to, and including, 1.7.32. This makes it possible for authenticated attackers to change the otherwise restricted settings within the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.0.9
The PWA for WP & AMP plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.72
The PWA for WP – Progressive Web Apps Made Simple plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.7.71 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
+ 3 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
—
|
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33 |
— |
Desconocido
|
< 1.7.33
|
1.7.33 |
— |
—
|
|
—
|
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33 |
— |
Desconocido
|
< 1.7.33
|
1.7.33 |
— |
—
|
|
—
|
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.0.9 |
— |
Desconocido
|
< 1.0.9
|
1.0.9 |
— |
—
|
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33
The plugin did not have a capability check in its pwaforwp_splashscreen_uploader function, and relied on CSRF check, however, the nonce was available to any authenticated user. As a result, any authenticated user (such as a subscriber) could call it and upload a malicious zip file containing a shell.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33
The plugin did not have a capability check in its pwaforwp_update_features_options function, and relied on CSRF check, however, the nonce was available to any authenticated user. As a result, any authenticated user (such as a subscriber) could call it and change the plugin's settings
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.0.9
The PWA for WP & AMP WordPress plugin was affected by a XSS security vulnerability.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Cómo solucionarlo
Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.
Alternativas más seguras / más establecidas