CVE-2026-12971: LearnPress < 4.4.4 - Instructor+ Server-Side Request Forgery via openai_apply_image_feature
Published Aug 10, 2026
·Updated
The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbitrary external hosts, a blind and bounded server-side request forgery.
Affected Software
1 affected component
WordPress LearnPress<4.4.4
Event History
Aug 10, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-12971?
CVE-2026-12971 has a risk score of 33, indicating a medium severity level.
2
How do I fix CVE-2026-12971?
To mitigate CVE-2026-12971, update the LearnPress plugin to version 4.4.4 or later.
3
What does CVE-2026-12971 exploit?
CVE-2026-12971 exploits a server-side request forgery vulnerability due to inadequate URL validation.
4
Who is affected by CVE-2026-12971?
Users with the instructor role in the LearnPress plugin prior to version 4.4.4 are affected by CVE-2026-12971.
5
What is the nature of the vulnerability in CVE-2026-12971?
CVE-2026-12971 is a blind and bounded server-side request forgery vulnerability.