CVE-2026-12971
N/A
N/A
Summary
The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbitrary external hosts, a blind and bounded server-side request forgery.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | LearnPress | 0 < 4.4.4 | affected |
Weaknesses
- CWE-918 Server-Side Request Forgery (SSRF)
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.