CVE-2026-12971
Received Received - Intake

Blind SSRF in LearnPress WordPress Plugin

Vulnerability report for CVE-2026-12971, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: WPScan

Description

The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbitrary external hosts, a blind and bounded server-side request forgery.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
thimpress learnpress to 4.4.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Server-Side Request Forgery (SSRF) vulnerability in the LearnPress WordPress plugin before version 4.4.4. It allows users with the instructor role to trick the server into making requests to arbitrary external hosts by supplying a URL without proper validation. The attack is blind and bounded, meaning the attacker cannot see the response but can still force the server to interact with unintended destinations.

Detection Guidance

Check the installed version of the LearnPress plugin. If it is below 4.4.4, the system is vulnerable. Use WordPress admin panel or run: wp plugin list --name=learnpress in the WordPress directory.

Impact Analysis

If you are a user with the instructor role on a vulnerable LearnPress site, an attacker could exploit this to make the server send requests to internal or external systems. This could lead to unauthorized access, data leakage, or further attacks against other systems. The impact is limited by the blind nature of the SSRF, but it still poses a security risk.

Compliance Impact

This vulnerability could potentially violate compliance requirements such as GDPR or HIPAA by allowing unauthorized data access or exposure through server-side interactions. Organizations using LearnPress must ensure they update to version 4.4.4 or later to mitigate this risk and maintain compliance.

Mitigation Strategies

Update the LearnPress plugin to version 4.4.4 or later immediately. Remove or restrict access for users with the instructor role until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12971. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart