PT-2026-71390 · WordPress · Kivicare

CVE-2026-13610

·

Published

2026-08-13

·

Updated

2026-08-13

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions KiviCare versions prior to 4.5.2
Description The KiviCare WordPress plugin contains a flaw in its unauthenticated registration endpoint that fails to restrict the roles that can be assigned during account creation. This allows an unauthenticated attacker to create a privileged clinic-staff (doctor) account, granting them full access to billing, clinic data, and patient records.
Recommendations Update KiviCare to version 4.5.2 or later.

Exploit

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13610

Affected Products

Kivicare