PatchSiren cyber security CVE debrief
CVE-2026-12971 LearnPress CVE debrief
The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbitrary external hosts, a blind and bounded server-side request forgery. This vulnerability allows users with instructor roles to potentially induce the server to make requests to external hosts, which could lead to information disclosure or other unintended consequences. The vulnerability is considered a blind and bounded server-side request forgery. Evidence from WPScan indicates a vulnerability in LearnPress plugin before version 4.4.4.
- Vendor
- LearnPress
- Product
- LearnPress Plugin
- CVSS
- LOW 2.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-10
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-10
- Advisory updated
- 2026-08-26
Who should care
Users of LearnPress plugin, especially those with instructor roles, should verify their plugin version and take necessary precautions. Additionally, security teams and vulnerability management teams should be aware of this vulnerability and review their environments for potential exposure. Platform operators and administrators should also be aware of this vulnerability and take steps to mitigate it.
Technical summary
The LearnPress WordPress plugin before 4.4.4 is vulnerable to server-side request forgery due to lack of validation on user-supplied URLs. This vulnerability allows users with the instructor role to potentially induce the server to make requests to external hosts, which could lead to information disclosure or other unintended consequences. The vulnerability is considered a blind and bounded server-side request forgery.
Defensive priority
Verify LearnPress plugin version and restrict instructor role permissions.
Recommended defensive actions
- Verify LearnPress plugin version
- Restrict instructor role permissions
- Monitor for suspicious requests
- Review compensating controls for exposed systems
- Check relevant monitoring, detection, and logs for exposed assets
- Track exceptions and retest remediated assets
- Confirm whether affected product deployments exist in managed environments
Evidence notes
The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbitrary external hosts, a blind and bounded server-side request forgery. Evidence from WPScan indicates a vulnerability in LearnPress plugin before version 4.4.4. The vulnerability allows users with instructor roles to potentially induce the server to make requests to external hosts, which could lead to information disclosure or other unintended consequences. Defenders should verify their LearnPress plugin version, restrict instructor role permissions, and monitor for suspicious requests.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-12971 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-12971
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-12971 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-12971
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/ef69bd9d-ec2a-4526-b2b9-51948fa76980/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.