CVE-2026-12971: The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowi
infovulnerability
security
Summary
CVE-2026-12971 is a vulnerability in the LearnPress WordPress plugin (a learning management system plugin) before version 4.4.4 where the server doesn't check if URLs are safe before fetching them. This allows instructors to trick the server into making requests to any external website, which is called SSRF (server-side request forgery, where an attacker makes a server send requests on their behalf).
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 0.0%
Disclosure Date
August 10, 2026
Classification
Attack SophisticationModerate
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-12971
First tracked: August 10, 2026 at 08:07 AM
Classified by LLM (prompt v3) · confidence: 95%