CVE-2026-12971
LearnPress SSRF: the instructor-role AI image-import feature fetches an arbitrary attacker-supplied URL server-side
- Severity
- medium
- Affected product
- learnpress
- Affected versions
- learnpress < 4.4.4
- Fixed in
- learnpress 4.4.4
- Added to NewScan
- 2026-08-10
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints learnpress from its response and reports this CVE when the detected version falls inside the affected range below.
The `openai_apply_image_feature` handler fetches a user-supplied URL with no allow-list, so an authenticated Instructor can make the server issue requests to internal hosts / cloud metadata (SSRF). Requires the Instructor role, not unauthenticated - the finding is still worth recording because LearnPress ships open instructor self-registration in its default course-marketplace setup. Version source: scan_wordpress mines every referenced plugin slug from asset `?ver=` and refines it against `/wp-content/plugins/learnpress/readme.txt` `Stable tag:`, the same generic per-slug join as the other WordPress rows in this pack - no new code needed. PoC: https://wpscan.com/vulnerability/ef69bd9d-ec2a-4526-b2b9-51948fa76980/
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →