CVE-2026-13610
Received Received - Intake

Unauthenticated Privilege Escalation in KiviCare WordPress Plugin

Vulnerability report for CVE-2026-13610, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: WPScan

Description

The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kivicare kivicare to 4.5.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The KiviCare WordPress plugin before version 4.5.2 has a vulnerability where its unauthenticated registration endpoint does not restrict assignable roles. This allows attackers to create a privileged clinic-staff account, specifically a doctor role, without authentication.

Detection Guidance

Check if the KiviCare WordPress plugin version is below 4.5.2 by inspecting the plugin files or WordPress admin panel. Look for unauthorized user accounts with the 'doctor' role in the WordPress user management section.

Impact Analysis

An attacker exploiting this vulnerability could gain full access to sensitive patient records, billing information, and clinic data. This could lead to unauthorized data exposure, manipulation, or theft of confidential information.

Compliance Impact

This vulnerability likely violates compliance requirements under GDPR and HIPAA due to unauthorized access to protected health information. It could result in legal penalties, data breach notifications, and reputational damage for affected organizations.

Mitigation Strategies

Immediately update the KiviCare plugin to version 4.5.2 or later. Review all user accounts for any unauthorized 'doctor' role accounts and remove them. Monitor for suspicious activity in patient records or billing data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13610. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart