The LearnPress WordPress plugin before 4.4.4 does not...
Low severity
Unreviewed
Published
Aug 10, 2026
to the GitHub Advisory Database
•
Updated Aug 11, 2026
Description
Published by the National Vulnerability Database
Aug 10, 2026
Published to the GitHub Advisory Database
Aug 10, 2026
Last updated
Aug 11, 2026
The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbitrary external hosts, a blind and bounded server-side request forgery.
References