CVE · Medium

CVE-2026-5108 — Super Progressive Web Apps [super-progressive-web-apps] < 2.2.44

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-5108 Super Progressive Web Apps [super-progressive-web-apps] < 2.2.44 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.4 < 2.2.44 2.2.44 2026-08-04

CVE-2026-5108

A critical vulnerability exists in the Super Progressive Web Apps plugin for WordPress due to inadequate handling of user input. Specifically, the `offline_message_txt` setting is not properly sanitized or escaped when stored and later displayed on the frontend through JavaScript, allowing attackers with elevated privileges to inject malicious scripts that will execute whenever a user interacts with the offline snackbar feature. This flaw affects all versions up to 2.2.43.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.