PWA plugin is bringing the power of the Progressive Web Apps to the WP & AMP to take the user experience to the next level.
What this plugin does
- Slug:
pwa-for-wp
- Author: Magazine3
- 20000+ active installs
- 92/100 rating (229 reviews on wordpress.org)
- 1568478 all-time downloads
- On WordPress.org since 2018-08-16
cachemanifestofflineprogressive web appspwa
Maintenance status
- Last updated: 2026-07-14 2:12pm GMT
- Tested up to WordPress: 7.0.2
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
3 known CVEs on file for PWA for WP - Progressive Web Apps Made Simple.
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-47318
|
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.73 |
Missing Authorization |
Medium
4.3
|
< 1.7.73
|
1.7.73 |
2024-09-25 |
—
|
|
CVE-2021-4354
|
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33 |
Unrestricted Upload of File with Dangerous Type |
High
8.8
|
< 1.7.33
|
1.7.33 |
2023-06-07 |
—
|
|
CVE-2021-4366
|
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33 |
Missing Authorization |
Medium
4.3
|
< 1.7.33
|
1.7.33 |
2023-06-07 |
—
|
|
—
|
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33 |
— |
Unknown
|
< 1.7.33
|
1.7.33 |
2021-07-01 |
—
|
|
—
|
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33 |
— |
Unknown
|
< 1.7.33
|
1.7.33 |
2021-07-01 |
—
|
|
—
|
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33 |
— |
Unknown
|
< 1.7.33
|
1.7.33 |
2021-07-01 |
—
|
|
—
|
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.0.9 |
— |
Unknown
|
< 1.0.9
|
1.0.9 |
2019-03-25 |
—
|
|
—
|
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.72 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
4.8
|
< 1.7.72
|
1.7.72 |
0000-00-00 |
—
|
CVE-2024-47318
The PWA for WP & AMP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.7.72. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
Source:
Wordfence
CVE-2021-4354
The PWA for WP & AMP for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pwaforwp_splashscreen_uploader function in versions up to, and including, 1.7.32. This makes it possible for authenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
Source:
CVE.org
CVE-2021-4366
The PWA for WP & AMP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the pwaforwp_update_features_options function in versions up to, and including, 1.7.32. This makes it possible for authenticated attackers to change the otherwise restricted settings within the plugin.
Source:
CVE.org
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33
Authenticated Arbitrary File Upload vulnerability discovered by Jerome Bruandet in WordPress PWA for WP & AMP plugin (versions <= 1.7.32).
Source:
Patchstack
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33
The PWA for WP & AMP for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pwaforwp_splashscreen_uploader function in versions up to, and including, 1.7.32. This makes it possible for authenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
Source:
Wordfence
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33
The PWA for WP & AMP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the pwaforwp_update_features_options function in versions up to, and including, 1.7.32. This makes it possible for authenticated attackers to change the otherwise restricted settings within the plugin.
Source:
Wordfence
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.0.9
The PWA for WP & AMP plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages.
Source:
Wordfence
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.72
The PWA for WP – Progressive Web Apps Made Simple plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.7.71 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Source:
Wordfence
+ 3 more known vulnerabilities
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
—
|
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33 |
— |
Unknown
|
< 1.7.33
|
1.7.33 |
— |
—
|
|
—
|
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33 |
— |
Unknown
|
< 1.7.33
|
1.7.33 |
— |
—
|
|
—
|
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.0.9 |
— |
Unknown
|
< 1.0.9
|
1.0.9 |
— |
—
|
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33
The plugin did not have a capability check in its pwaforwp_splashscreen_uploader function, and relied on CSRF check, however, the nonce was available to any authenticated user. As a result, any authenticated user (such as a subscriber) could call it and upload a malicious zip file containing a shell.
Source:
WPScan
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.7.33
The plugin did not have a capability check in its pwaforwp_update_features_options function, and relied on CSRF check, however, the nonce was available to any authenticated user. As a result, any authenticated user (such as a subscriber) could call it and change the plugin's settings
Source:
WPScan
PWA for WP – Progressive Web Apps Made Simple [pwa-for-wp] < 1.0.9
The PWA for WP & AMP WordPress plugin was affected by a XSS security vulnerability.
Source:
WPScan
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives