Description
The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data.
Published: 2026-08-13
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the KiviCare WordPress plugin allows anyone to register a new clinic‑staff user without authentication and to assign any role. The endpoint accepts a role parameter that determines account privileges. An attacker can therefore create an active doctor account that has full read and write access to patient records, billing, and clinic data. This leads to a total compromise of confidentiality, integrity, and availability of sensitive medical information.

Affected Systems

WordPress sites that have installed a KiviCare plugin version earlier than 4.5.2 are impacted. The plugin is listed under the vendor Unknown:KiviCare. Any site that exposes the default registration endpoint is susceptible; if the plugin is disabled or the endpoint is disabled, the vulnerability is mitigated.

Risk and Exploitability

Because no authentication is required, the attack vector is minimal; an attacker just needs to send an HTTP request to the registration URL. EPSS score is less than 1% and the issue is not in the CISA KEV catalog, but the potential for full privileged account creation means that exploitation would deliver a high‑impact outcome. The lack of access controls makes it highly exploitable in practice. The CVSS score of 7.5 indicates a medium‑to‑high severity.

Generated by OpenCVE AI on August 14, 2026 at 20:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the KiviCare plugin to version 4.5.2 or later
  • If an upgrade cannot be performed immediately, disable the plugin’s unauthenticated registration endpoint or require authentication before role assignment
  • Audit and remove any unexpected or unauthorized doctor or privileged user accounts

Generated by OpenCVE AI on August 14, 2026 at 20:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Iqonic
Iqonic kivicare
Wordpress
Wordpress wordpress
Vendors & Products Iqonic
Iqonic kivicare
Wordpress
Wordpress wordpress

Thu, 13 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Thu, 13 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data.
Title KiviCare < 4.5.2 - Unauthenticated Privilege Escalation via Registration
References

Subscriptions

Iqonic Kivicare
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-14T19:00:23.813Z

Reserved: 2026-06-29T09:16:05.014Z

Link: CVE-2026-13610

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-13T06:17:37.780

Modified: 2026-08-26T16:30:52.723

Link: CVE-2026-13610

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T20:45:03Z

Weaknesses