CVE-2026-12971
LearnPress < 4.4.4 - Instructor+ Server-Side Request Forgery via openai_apply_image_feature
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbitrary external hosts, a blind and bounded server-side request forgery.
| Vendor | unknown |
| Product | learnpress |
| Published | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown learnpress
Be the first to know when new unknown vulnerabilities affecting unknown learnpress are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / LearnPress
0 < 4.4.4
References
Credits
Meher Sudhakar Abbireddi WPScan