What is CVE-2026-12971?
CVE-2026-12971 was identified in the LearnPress WordPress plugin. This allows instructors to trigger a blind Server-Side Request Forgery (SSRF) by providing an unvalidated URL, causing the server to issue requests to arbitrary external hosts. The recommended fix is to update the plugin to version 4.4.4 or later.
Azərbaycanca: CVE-2026-12971, LearnPress WordPress plaginində aşkar edilmişdir. Təlimçi roluna malik istifadəçilər, serverin arbitrary xarici hostlara sorğu göndərməsinə səbəb ola bilər. Bu problemi aradan qaldırmaq üçün plagini 4.4.4 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
What type of attack does CVE-2026-12971 allow through the LearnPress plugin?
This vulnerability allows users with the instructor role to perform a blind Server-Side Request Forgery (SSRF) attack, causing the server to issue requests to arbitrary external hosts.
To which version should the LearnPress plugin be updated to mitigate CVE-2026-12971?
To fix this issue, the LearnPress plugin should be updated to version 4.4.4 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.