Description
The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data.
Published: 2026-08-13
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the KiviCare WordPress plugin allows anyone to register a new clinic‑staff user without authentication and to assign any role. The endpoint accepts a role parameter that determines account privileges. An attacker can therefore create an active doctor account that has full read and write access to patient records, billing, and clinic data. This leads to a total compromise of confidentiality, integrity, and availability of sensitive medical information.

Affected Systems

WordPress sites that have installed a KiviCare plugin version earlier than 4.5.2 are impacted. The plugin is listed under the vendor Unknown:KiviCare. Any site that exposes the default registration endpoint is susceptible; if the plugin is disabled or the endpoint is disabled, the vulnerability is mitigated.

Risk and Exploitability

Because no authentication is required, the attack vector is minimal; an attacker just needs to send an HTTP request to the registration URL. EPSS is not available and the issue is not in the CISA KEV catalog, but the potential for full privileged account creation means that exploitation would deliver a high‑impact outcome. The lack of access controls makes it highly exploitable in practice.

Generated by OpenCVE AI on August 13, 2026 at 07:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the KiviCare plugin to version 4.5.2 or later
  • If an upgrade cannot be performed immediately, disable the plugin’s unauthenticated registration endpoint or require authentication before role assignment
  • Audit and remove any unexpected or unauthorized doctor or privileged user accounts

Generated by OpenCVE AI on August 13, 2026 at 07:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Thu, 13 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data.
Title KiviCare < 4.5.2 - Unauthenticated Privilege Escalation via Registration
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-13T06:00:12.789Z

Reserved: 2026-06-29T09:16:05.014Z

Link: CVE-2026-13610

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T06:17:37.780

Modified: 2026-08-13T06:17:37.780

Link: CVE-2026-13610

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T08:00:04Z

Weaknesses