PT-2026-57138 · WordPress · Kivicare
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
KiviCare – Clinic & Patient Management System (EHR) versions prior to 4.4.1
Description
An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. Unauthenticated attackers can exploit this to mark pending appointments as Confirmed and forge completed payment records in the
wp kc payments appointment mappings table using a supplied payment ID, effectively bypassing the payment process. This is possible on default installations because the gateway resolution logic returns all registered gateways regardless of their admin-enabled status, ensuring the manual (KCPayLater) gateway is always selectable via the /payment-success REST endpoint.Recommendations
Update the plugin to a version newer than 4.4.0.
Restrict access to the
/payment-success REST endpoint to minimize the risk of exploitation.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kivicare