CVE-2025-66095: WordPress KiviCare plugin <= 3.6.13 - SQL Injection vulnerability
Published Nov 21, 2025
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows SQL Injection.This issue affects KiviCare: from n/a through <= 3.6.13.
Affected Software
2 affected components
Iqonic Design KiviCare<=3.6.13
WordPress KiviCare plugin<=3.6.13
Event History
Nov 21, 2025
CVE Published
via MITRE·12:29 PM
Data Sourced
via MITRE·12:29 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-66095?
CVE-2025-66095 has a high severity rating due to its potential for SQL Injection vulnerabilities.
2
How do I fix CVE-2025-66095?
To fix CVE-2025-66095, update the Iqonic Design KiviCare and WordPress KiviCare plugin to version 3.6.14 or later.
3
What type of vulnerability is CVE-2025-66095?
CVE-2025-66095 is classified as an SQL Injection vulnerability.
4
What versions of KiviCare are affected by CVE-2025-66095?
CVE-2025-66095 affects KiviCare versions up to and including 3.6.13.
5
Can CVE-2025-66095 lead to data breaches?
Yes, CVE-2025-66095 can potentially lead to data breaches if exploited.