Impact
The vulnerability allows an authenticated administrator to embed malicious scripts in the offline message setting. When the offline snackbar is displayed to site visitors, the unescaped text is injected into the page via innerHTML, causing the script to run with the page’s privileges.
Affected Systems
The affected product is the WordPress plugin Super Progressive Web Apps, versions 2.2.43 and earlier. Any site running a vulnerable version can be compromised by an admin user.
Risk and Exploitability
With a CVSS score of 4.4, the risk is considered low; however, it requires administrative credentials, which limits the number of potential attackers. Because it is not listed in KEV and the EPSS score is unavailable, it is unlikely to be widely exploited at present, but the ability to run arbitrary scripts remains a significant threat if an attacker gains admin access.
OpenCVE Enrichment