Impact
The vulnerability in the KiviCare WordPress plugin allows anyone to register a new clinic‑staff user without authentication and to assign any role. The endpoint accepts a role parameter that determines account privileges. An attacker can therefore create an active doctor account that has full read and write access to patient records, billing, and clinic data. This leads to a total compromise of confidentiality, integrity, and availability of sensitive medical information.
Affected Systems
WordPress sites that have installed a KiviCare plugin version earlier than 4.5.2 are impacted. The plugin is listed under the vendor Unknown:KiviCare. Any site that exposes the default registration endpoint is susceptible; if the plugin is disabled or the endpoint is disabled, the vulnerability is mitigated.
Risk and Exploitability
Because no authentication is required, the attack vector is minimal; an attacker just needs to send an HTTP request to the registration URL. EPSS is not available and the issue is not in the CISA KEV catalog, but the potential for full privileged account creation means that exploitation would deliver a high‑impact outcome. The lack of access controls makes it highly exploitable in practice.
OpenCVE Enrichment