CVE-2026-19416
Deferred Deferred - Pending Action

Authenticated Patient Access Bypass in KiviCare WordPress Plugin

Vulnerability report for CVE-2026-19416, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-26

Assigner: WPScan

Description

The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user owns the appointment being modified, allowing authenticated patient-level users to cancel and reschedule other patients' appointments.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-26
Generated
2026-09-08
AI Q&A
2026-08-19
EPSS Evaluated
2026-09-07
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
kivicare kivicare_wordpress_plugin to 4.5.4 (exc)
kivicare kivicare to 4.5.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The KiviCare WordPress plugin before version 4.5.4 has an Insecure Direct Object Reference (IDOR) vulnerability. This allows authenticated patient-level users to modify appointments that belong to other patients without proper authorization checks. Specifically, these users can cancel or reschedule appointments they do not own.

Detection Guidance

Check the installed version of the KiviCare WordPress plugin. If it is below 4.5.4, the system is vulnerable. Use WordPress admin panel or run SQL queries on the database to verify plugin versions.

Impact Analysis

This vulnerability could allow unauthorized users to disrupt scheduled appointments by canceling or rescheduling them. This may lead to confusion, missed appointments, and potential service disruptions for legitimate patients.

Compliance Impact

This vulnerability could potentially violate compliance with GDPR and HIPAA by allowing unauthorized users to modify or cancel appointments belonging to other patients. Unauthorized access to patient data or appointment details may lead to breaches of confidentiality and data integrity requirements under these regulations.

Mitigation Strategies

Update the KiviCare plugin to version 4.5.4 or later immediately. Ensure no unauthorized modifications have occurred to appointments. Review user access logs for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19416. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart