CVE-2026-12971: Unknown Learnpress
Low severity, CVSS 2.2. EPSS: 0.2% chance of exploitation in the next 30 days.
The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbitrary external hosts, a blind and bounded server-side request forgery.
Affected products
- Unknown Learnpress: before 4.4.4 (fixed in 4.4.4)
Published 2026-08-10. Last modified 2026-08-26.