WP Clinic
Log in Sign up

PLUGIN SECURITY

Is PWA for WP - Progressive Web Apps Made Simple safe?

PWA plugin is bringing the power of the Progressive Web Apps to the WP & AMP to take the user experience to the next level.

What this plugin does

  • Slug: pwa-for-wp
  • Author: Magazine3
  • 20000+ active installs
  • 92/100 rating (229 reviews on wordpress.org)
  • 1568478 all-time downloads
  • On WordPress.org since 2018-08-16

cachemanifestofflineprogressive web appspwa

Maintenance status

  • Last updated: 2026-07-14 2:12pm GMT
  • Tested up to WordPress: 7.0.2
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

3 known CVEs on file for PWA for WP - Progressive Web Apps Made Simple.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-47318 PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.73 Missing Authorization Medium 4.3 < 1.7.73 1.7.73 2024-09-25
CVE-2021-4354 PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33 Unrestricted Upload of File with Dangerous Type High 8.8 < 1.7.33 1.7.33 2023-06-07
CVE-2021-4366 PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33 Missing Authorization Medium 4.3 < 1.7.33 1.7.33 2023-06-07
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33 Unknown < 1.7.33 1.7.33 2021-07-01
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33 Unknown < 1.7.33 1.7.33 2021-07-01
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33 Unknown < 1.7.33 1.7.33 2021-07-01
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.0.9 Unknown < 1.0.9 1.0.9 2019-03-25
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.72 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 1.7.72 1.7.72 0000-00-00

CVE-2024-47318

The PWA for WP & AMP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.7.72. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

Source: Wordfence

CVE-2021-4354

The PWA for WP & AMP for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pwaforwp_splashscreen_uploader function in versions up to, and including, 1.7.32. This makes it possible for authenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

Source: CVE.org

CVE-2021-4366

The PWA for WP & AMP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the pwaforwp_update_features_options function in versions up to, and including, 1.7.32. This makes it possible for authenticated attackers to change the otherwise restricted settings within the plugin.

Source: CVE.org

PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33

Authenticated Arbitrary File Upload vulnerability discovered by Jerome Bruandet in WordPress PWA for WP & AMP plugin (versions <= 1.7.32).

Source: Patchstack

PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33

The PWA for WP & AMP for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pwaforwp_splashscreen_uploader function in versions up to, and including, 1.7.32. This makes it possible for authenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

Source: Wordfence

PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33

The PWA for WP & AMP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the pwaforwp_update_features_options function in versions up to, and including, 1.7.32. This makes it possible for authenticated attackers to change the otherwise restricted settings within the plugin.

Source: Wordfence

PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.0.9

The PWA for WP & AMP plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages.

Source: Wordfence

PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.72

The PWA for WP – Progressive Web Apps Made Simple plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.7.71 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Source: Wordfence

+ 3 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33 Unknown < 1.7.33 1.7.33
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33 Unknown < 1.7.33 1.7.33
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.0.9 Unknown < 1.0.9 1.0.9

PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33

The plugin did not have a capability check in its pwaforwp_splashscreen_uploader function, and relied on CSRF check, however, the nonce was available to any authenticated user. As a result, any authenticated user (such as a subscriber) could call it and upload a malicious zip file containing a shell.

Source: WPScan

PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33

The plugin did not have a capability check in its pwaforwp_update_features_options function, and relied on CSRF check, however, the nonce was available to any authenticated user. As a result, any authenticated user (such as a subscriber) could call it and change the plugin's settings

Source: WPScan

PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.0.9

The PWA for WP & AMP WordPress plugin was affected by a XSS security vulnerability.

Source: WPScan

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.