Vulnerability Description
The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbitrary external hosts, a blind and bounded server-side request forgery.
CVSS Score
LOW
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-12971?
CVE-2026-12971 is a vulnerability with a CVSS score of 2.2 (LOW). The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbi...
How severe is CVE-2026-12971?
CVE-2026-12971 has been rated LOW with a CVSS base score of 2.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-12971?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.