A vulnerability labeled as problematic has been found in Super Progressive Web Apps Plugin up to 2.2.43 on WordPress. Impacted is the function
wp_localize_script of the component Offline Message. Executing a manipulation of the argument offline_message_txt can lead to cross site scripting.
This vulnerability is handled as CVE-2026-5108. The attack can be executed remotely. There is not any exploit available.