GHSA-378w-q773-hrghHighCVSS 7.5

The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its...

Published
August 13, 2026
Last Modified
August 14, 2026

🔗 CVE IDs covered (1)

📋 Description

The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data.

🔗 References (3)