CVE-2026-13611
Received Received - Intake

Unauthenticated Access to Patient Data in KiviCare Plugin

Vulnerability report for CVE-2026-13611, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: WPScan

Description

The KiviCare WordPress plugin before 4.5.5 does not perform authorization checks on some of its REST endpoints, allowing unauthenticated attackers to disclose the patient roster and, when a payment gateway is configured, the payment gateway secret key.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kivicare kivicare to 4.5.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the KiviCare WordPress plugin before version 4.5.5 allows unauthenticated attackers to access sensitive patient data due to missing authorization checks on certain REST endpoints. Attackers can view the entire patient roster and, if a payment gateway is configured, obtain the payment gateway's secret key.

Detection Guidance

To detect this vulnerability, check if your KiviCare WordPress plugin version is below 4.5.5. You can use WordPress admin panel or run the command: wp plugin list | grep kivicare. If outdated, update immediately.

Impact Analysis

Unauthenticated attackers could access patient records, including personal and medical information, and if a payment gateway is used, they could also steal the secret key, potentially leading to financial fraud or further data breaches.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA due to unauthorized access to protected health information (PHI). It could result in legal penalties, loss of patient trust, and regulatory fines for non-compliance with data protection requirements.

Mitigation Strategies

Immediately update the KiviCare plugin to version 4.5.5 or later. If immediate update is not possible, disable the plugin temporarily until patched. Review patient data access logs for unauthorized activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13611. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart