CyberRota Analysis
AI-GeneratedThe LearnPress WordPress plugin prior to version 4.4.4 is vulnerable to a blind and bounded server-side request forgery due to inadequate validation of user-supplied URLs, allowing users with instructor privileges to make the server issue requests to arbitrary external hosts. This vulnerability could lead to exposure of sensitive data or further exploitation of the server environment. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential risks.
Original NVD Description
The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbitrary external hosts, a blind and bounded server-side request forgery.