A vulnerability labeled as problematic has been found in Super Progressive Web Apps Plugin up to 2.2.43 on WordPress. Impacted is the function wp_localize_script of the component Offline Message. Executing a manipulation of the argument offline_message_txt can lead to cross site scripting.

This vulnerability is handled as CVE-2026-5108. The attack can be executed remotely. There is not any exploit available.