WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in PWA for WP – Progressive Web Apps Made Simple

PWA plugin is bringing the power of the Progressive Web Apps to the WP & AMP to take the user experience to the next level.

5Reported vulnerabilities
8.8Highest CVSS score
1.7.87Latest version
20,000+Active installs

What to do now

Update PWA for WP – Progressive Web Apps Made Simple to 1.7.72 or later. 5 of these have a fixed version available. Updating resolves them.

Plugin last updated: July 14, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2021-4354 High 8.8 1.8% Before 1.7.33 1.7.33 June 7, 2023
CVE-2024-7759 Medium 4.8 0.3% Before 1.7.72 1.7.72 May 15, 2025
CVE-2021-4366 Medium 4.3 0.6% Before 1.7.33 1.7.33 June 7, 2023
WF-934545ff-8886-47c7-ad50-0e5ff513a26c High 7.2 Before 1.0.9 1.0.9 March 25, 2019
CVE-2024-47318 Medium 4.3 0.3% 1.7.72 and earlier 1.7.73 September 25, 2024

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.