Impact
KiviCare, a WordPress plugin that manages patient records, contains an insecure direct object reference that allows any authenticated patient-level user to access details belonging to other patients. The flaw stems from the plugin failing to verify ownership of the records being requested, meaning a user can read bills, invoices, and appointment information that should be confidential. Because this is purely an information disclosure issue, an attacker gains only read access and no control over the system, but the breach could cause significant privacy violations and undermine trust in the healthcare platform.
Affected Systems
All installations of the KiviCare WordPress plugin prior to version 4.5.2 are affected. The vulnerability applies to the core plugin itself; no additional modules or external products are mentioned in the advisory.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating no known exploited reports. Because the flaw is trivial to detect and leverage once a user is logged in, the risk remains moderate for sites storing sensitive health‑related data, however the CVSS score of 4.3 indicates a low severity information‑disclosure issue. Users should still apply the official patch to mitigate the risk.
OpenCVE Enrichment