WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro PWA for WP - Progressive Web Apps Made Simple?

PWA plugin is bringing the power of the Progressive Web Apps to the WP & AMP to take the user experience to the next level.

Qué hace este plugin

  • Slug: pwa-for-wp
  • Autor: Magazine3
  • 20000+ instalaciones activas
  • 92/100 calificación (229 reseñas en wordpress.org)
  • 1568478 descargas totales
  • En WordPress.org desde 2018-08-16

cachemanifestofflineprogressive web appspwa

Estado de mantenimiento

  • Última actualización: 2026-07-14 2:12pm GMT
  • Probado hasta WordPress: 7.0.2
  • PHP máximo soportado (analizado): 8.4

Vulnerabilidades conocidas

3 CVEs conocidos registrados para PWA for WP - Progressive Web Apps Made Simple.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2024-47318 PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.73 Falta de control de autorización Media 4,3 < 1.7.73 1.7.73 2024-09-25
CVE-2021-4354 PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33 Carga de archivos sin restricción de tipo peligroso Alta 8,8 < 1.7.33 1.7.33 2023-06-07
CVE-2021-4366 PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33 Falta de control de autorización Media 4,3 < 1.7.33 1.7.33 2023-06-07
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33 Desconocido < 1.7.33 1.7.33 2021-07-01
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33 Desconocido < 1.7.33 1.7.33 2021-07-01
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33 Desconocido < 1.7.33 1.7.33 2021-07-01
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.0.9 Desconocido < 1.0.9 1.0.9 2019-03-25
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.72 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 1.7.72 1.7.72 0000-00-00

CVE-2024-47318

The PWA for WP & AMP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.7.72. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2021-4354

The PWA for WP & AMP for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pwaforwp_splashscreen_uploader function in versions up to, and including, 1.7.32. This makes it possible for authenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2021-4366

The PWA for WP & AMP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the pwaforwp_update_features_options function in versions up to, and including, 1.7.32. This makes it possible for authenticated attackers to change the otherwise restricted settings within the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33

Authenticated Arbitrary File Upload vulnerability discovered by Jerome Bruandet in WordPress PWA for WP & AMP plugin (versions <= 1.7.32).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33

The PWA for WP & AMP for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pwaforwp_splashscreen_uploader function in versions up to, and including, 1.7.32. This makes it possible for authenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33

The PWA for WP & AMP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the pwaforwp_update_features_options function in versions up to, and including, 1.7.32. This makes it possible for authenticated attackers to change the otherwise restricted settings within the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.0.9

The PWA for WP & AMP plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.72

The PWA for WP – Progressive Web Apps Made Simple plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.7.71 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

+ 3 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33 Desconocido < 1.7.33 1.7.33
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33 Desconocido < 1.7.33 1.7.33
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.0.9 Desconocido < 1.0.9 1.0.9

PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33

The plugin did not have a capability check in its pwaforwp_splashscreen_uploader function, and relied on CSRF check, however, the nonce was available to any authenticated user. As a result, any authenticated user (such as a subscriber) could call it and upload a malicious zip file containing a shell.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33

The plugin did not have a capability check in its pwaforwp_update_features_options function, and relied on CSRF check, however, the nonce was available to any authenticated user. As a result, any authenticated user (such as a subscriber) could call it and change the plugin's settings

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.0.9

The PWA for WP & AMP WordPress plugin was affected by a XSS security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Cómo solucionarlo

Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.