Kivicare

WordPress plugin · kivicare · WordPress.org ↗
0
Critical
2
High
6
Known total
0
Unfixed
Running Kivicare on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
HIGH
CVSS 7.5
KiviCare < 4.5.2 - Unauthenticated Privilege Escalation via Registration
CVE.org
>=0, <4.5.2 v4.5.2 CVE-2026-13610 Aug 13, 2026
HIGH
CVSS 8.8
KiviCare < 4.5.2 - Doctor/Receptionist+ SQL Injection via settings/listing REST Endpoint
CVE.org
>=0, <4.5.2 v4.5.2 CVE-2026-13613 Aug 12, 2026
MEDIUM
CVSS 5.3
KiviCare – Clinic & Patient Management System (EHR) < 4.5.5 - Unauthenticated Patient Data Disclosure
CVE.org
>=0, <4.5.5 v4.5.5 CVE-2026-13611 Sep 1, 2026
MEDIUM
CVSS 4.3
KiviCare < 4.5.4 - Patient+ Cross-Patient Appointment Modification via IDOR
CVE.org
>=0, <4.5.4 v4.5.4 CVE-2026-19416 Aug 19, 2026
MEDIUM
CVSS 6.5
KiviCare < 4.5.4 - Patient+ Arbitrary Media Attachment Read via IDOR
CVE.org
>=0, <4.5.4 v4.5.4 CVE-2026-19417 Aug 19, 2026
MEDIUM
CVSS 4.3
KiviCare < 4.5.2 - Patient+ Cross-Patient Bill, Invoice and Appointment Disclosure via IDOR
CVE.org
>=0, <4.5.2 v4.5.2 CVE-2026-13612 Aug 12, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.