AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-12971

LOW · CVSS 2.2 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The LearnPress WordPress plugin prior to version 4.4.4 is vulnerable to a blind and bounded server-side request forgery due to inadequate validation of user-supplied URLs, allowing users with instructor privileges to make the server issue requests to arbitrary external hosts. This vulnerability could lead to exposure of sensitive data or further exploitation of the server environment. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential risks.

CVE
CVE-2026-12971
Severity
LOW
CVSS
2.2
EPSS
0.19%
WordPress

Original NVD Description

The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbitrary external hosts, a blind and bounded server-side request forgery.