CVE-2023-2628: KiviCare Management System < 3.2.1 - Multiple CSRF
The KiviCare WordPress plugin before 3.2.1 does not have CSRF checks (either flawed or missing completely) in various AJAX actions, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks. This includes, but is not limited to: Delete arbitrary appointments/medical records/etc, create/update various users (patients, doctors etc)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2628?
The severity of CVE-2023-2628 is high with a severity value of 8.8.
What is CVE-2023-2628?
CVE-2023-2628 is a vulnerability in the KiviCare WordPress plugin before version 3.2.1 that lacks CSRF checks, allowing attackers to perform unwanted actions via CSRF attacks.
How does CVE-2023-2628 affect the KiviCare WordPress plugin?
CVE-2023-2628 affects the KiviCare WordPress plugin before version 3.2.1 by not having CSRF checks in various AJAX actions, potentially enabling attackers to make logged in users perform unwanted actions.
What is the affected software of CVE-2023-2628?
The affected software of CVE-2023-2628 is the KiviCare WordPress plugin before version 3.2.1.
How can I fix CVE-2023-2628?
To fix CVE-2023-2628, it is recommended to update the KiviCare WordPress plugin to version 3.2.1 or later.