← All CVEs NewScan detects
medium

CVE-2026-12971

LearnPress SSRF: the instructor-role AI image-import feature fetches an arbitrary attacker-supplied URL server-side

Severity
medium
Affected product
learnpress
Affected versions
learnpress < 4.4.4
Fixed in
learnpress 4.4.4
Added to NewScan
2026-08-10
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints learnpress from its response and reports this CVE when the detected version falls inside the affected range below.

The `openai_apply_image_feature` handler fetches a user-supplied URL with no allow-list, so an authenticated Instructor can make the server issue requests to internal hosts / cloud metadata (SSRF). Requires the Instructor role, not unauthenticated - the finding is still worth recording because LearnPress ships open instructor self-registration in its default course-marketplace setup. Version source: scan_wordpress mines every referenced plugin slug from asset `?ver=` and refines it against `/wp-content/plugins/learnpress/readme.txt` `Stable tag:`, the same generic per-slug join as the other WordPress rows in this pack - no new code needed. PoC: https://wpscan.com/vulnerability/ef69bd9d-ec2a-4526-b2b9-51948fa76980/

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →