Medium 4.8
2025-05-19< 1.7.72
WordPress PWA for WP & AMP Plugin < 1.7.72 Administrator+ Stored XSS vulnerability is vulnerable to Cross Site Scripting (XSS)
Minimum safe version
1.7.73
Update to 1.7.73 or later to address 11 fixable vulnerabilities
WordPress PWA for WP & AMP Plugin < 1.7.72 Administrator+ Stored XSS vulnerability is vulnerable to Cross Site Scripting (XSS)
CVE-2024-47318
PWA for WP <= 1.0.8 - XSS
PWA for WP & AMP < 1.7.33 - Authenticated (Subscriber+) Settings Change
PWA for WP & AMP < 1.7.33 - Authenticated (Subscriber+) Arbitrary File Upload
CVE-2021-4366
CVE-2021-4354
PWA for WP & AMP Plugin <= 1.0.8 - Cross-Site Scripting
PWA for WP & AMP < = 1.7.32 - Missing Authorization
PWA for WP & AMP <= 1.7.32 - Arbitrary File Upload
WordPress PWA for WP & AMP plugin <= 1.7.32 - Authenticated Arbitrary File Upload vulnerability