Description
WordPress Plugin PWA for WP & AMP is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change plugin�s settings, or even upload arbitrary files. WordPress Plugin PWA for WP & AMP version 1.7.32 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.7.33 or latest
References
Related Vulnerabilities
XWiki Improper Encoding or Escaping of Output Vulnerability (CVE-2023-45135)
WordPress Plugin LearnPress-WordPress LMS Cross-Site Scripting (4.1.3.1)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-6131)
Internet Information Services Other Vulnerability (CVE-2000-1104)