Impact
The vulnerability is a classic SQL injection (CWE-89) in the KiviCare plugin. The unsanitized 'orderby' parameter allows an authenticated user with doctor-level or higher access to inject malicious SQL. This can lead to extraction of sensitive information, such as patient records, from the WordPress database. The injection does, receptionists, or clinic administrators who possess the doctor_session_list capability.
Affected Systems
Affected systems are WordPress environments running the KiviCare – Clinic & Patient Management System plugin version 4.5.0 or earlier. The plugin is provided by iqonicdesign under the KiviCare product line. Users who have any role that grants doctor_session_list capability are potentially impacted. No specific version beyond 4.5.0 has been identified as vulnerable.
Risk and Exploitability
The CVSS metric scores 6.5, indicating a moderate severity. The EPSS score is less than 1%, suggesting a low exploitation probability at the time of the analysis and the vulnerability has not been flagged in CISA KEV. The attack vector is inferred to be local or internal, as the attacker hold doctor-level or higher privileges. If the vulnerability is exploited, an attacker could gain read access to confidential database entries, potentially violating privacy regulations and exposing sensitive patient information.
OpenCVE Enrichment