Back

LOW

LearnPress < 4.4.4 - Instructor+ Server-Side Request Forgery via openai_apply_image_feature

Published Aug 10, 2026

Description

The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbitrary external hosts, a blind and bounded server-side request forgery.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Aug 10, 2026
Updated Aug 11, 2026
Reserved Jun 23, 2026
CISA Vulnrichment
Updated Aug 11, 2026
NVD
Status Deferred
Modified Aug 26, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner WPScan
Published Aug 10, 2026
Updated Aug 11, 2026
Exploited since n/a
EUVD-2026-55024