Impact
Iqonic Design's KiviCare plugin allows blind SQL injection through improper neutralization of special characters in SQL commands, potentially granting an attacker read or write access to the database and compromising confidentiality and integrity. The vulnerability is of the well‑known type CWE‑89 and can lead to serious data exposure or alteration if exploited.
Affected Systems
All WordPress sites running the KiviCare clinic management plugin version 3.6.16 or earlier are affected; the issue applies from the earliest released version through 3.6.16.
Risk and Exploitability
The vulnerability scores a CVSS 8.5, indicating high severity, but the EPSS is below 1%, suggesting that exploitation is currently unlikely. It is not listed in CISA's KEV catalog. The likely attack vector is application‑level, exploiting a publicly reachable input field within the plugin; no explicit authentication requirement is detailed, so the potential exists for both remote and authenticated attackers.
OpenCVE Enrichment