---
id: CVE-2026-12971
title: >-
  The LearnPress  WordPress plugin before 4.4.4 does not validate a
  user-supplied URL before the server fetches it, allowing users with the
  instructor role to induce the server to issue requests to arbitrary external
  hosts, a blind and bou…
summary: >-
  The LearnPress  WordPress plugin before 4.4.4 does not validate a
  user-supplied URL before the server fetches it, allowing users with the
  instructor role to induce the server to issue requests to arbitrary external
  hosts, a blind and bou…
severity: none
published: '2026-08-10'
updated: '2026-08-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-12971'
references:
  - url: 'https://wpscan.com/vulnerability/ef69bd9d-ec2a-4526-b2b9-51948fa76980/'
    label: contact@wpscan.com
tags:
  - nvd
ingestedAt: '2026-08-10T07:39:17.010Z'
epss: 0.00183
epssPercentile: 0.08159
---

## Overview

The LearnPress  WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbitrary external hosts, a blind and bounded server-side request forgery.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
