WP Clinic
Log in Sign up

PLUGIN SECURITY

Is Super Progressive Web Apps safe?

SuperPWA helps you convert your WordPress website into a Progressive Web App instantly.

What this plugin does

  • Slug: super-progressive-web-apps
  • Author: SuperPWA
  • 40000+ active installs
  • 92/100 rating (225 reviews on wordpress.org)
  • 2392786 all-time downloads
  • On WordPress.org since 2018-01-24

add to homescreenAndroid Appchrome appprogressive web appspwa

Maintenance status

  • Last updated: 2026-06-16 7:17am GMT
  • Tested up to WordPress: 7.0.2
  • Requires PHP: 5.3+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

1 known CVE on file for Super Progressive Web Apps. Reported between 2021 and 2023.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-48277 Super Progressive Web Apps [super-progressive-web-apps] < 2.2.22 Missing Authorization Medium 4.3 < 2.2.22 2.2.22 2023-11-22
Super Progressive Web Apps [super-progressive-web-apps] < 2.2.9 Unknown < 2.2.9 2.2.9 2022-11-29
Super Progressive Web Apps [super-progressive-web-apps] < 2.1.13 Unknown < 2.1.13 2.1.13 2021-06-29
Super Progressive Web Apps [super-progressive-web-apps] < 2.1.12 Unknown < 2.1.12 2.1.12
Super Progressive Web Apps [super-progressive-web-apps] < 2.1.13 Unknown < 2.1.13 2.1.13

CVE-2023-48277

No patched version is available. Abdi Pranata discovered and reported this Broken Access Control vulnerability in WordPress Super Progressive Web Apps Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has not been known to be fixed yet.

Source: Patchstack

Super Progressive Web Apps [super-progressive-web-apps] < 2.2.9

The Super Progressive Web Apps plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the superpwa_send_feedback function in versions up to, and including, 2.2.8. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to submit feedback to the plugin developers.

Source: Wordfence

Super Progressive Web Apps [super-progressive-web-apps] < 2.1.13

Authenticated Arbitrary File Upload vulnerability leading to Remote Code Execution (RCE) discovered by WPScan Team in WordPress Super Progressive Web Apps plugin (versions <= 2.1.12).

Source: Patchstack

Super Progressive Web Apps [super-progressive-web-apps] < 2.1.12

When the Apple Touch Icons & Splash Screen add-on is active, its superpwa_splashscreen_uploader AJAX action, does not properly check for CSRF, authorisation and the content of the uploaded archive file. This allows attackers to upload an archive with a PHP file, leading to RCE by either using a low privilege account (subscriber+) or a CSRF attack on any logged in user. v2.1.11 fixed the CSRF check, only. v2.1.12 added capability check.

Source: WPScan

Super Progressive Web Apps [super-progressive-web-apps] < 2.1.13

When the Apple Touch Icons & Splash Screen add-on is active, its superpwa_splashscreen_uploader AJAX action, did not properly check for authorisation and the content of the uploaded archive file. This allows high privilege users (admin+) to upload an archive with a PHP file, leading to RCE. v2.1.12 attempted to fix the issue by deleting potential malicious files, after extracting the archive, but was checking the wrong folder. And even if the correct folder was checked, a race condition could have been used to exploit the issue

Source: WPScan

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.