CVE-2026-13610: KiviCare < 4.5.2 - Unauthenticated Privilege Escalation via Registration
The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
KiviCare WordPress pluginto a version that resolves this vulnerability.Fixed in 4.5.2 - Compensating control
Restrict network access to the unauthenticated KiviCare registration endpoint so unauthenticated users cannot register clinic-staff (doctor) accounts with privileged permissions until the plugin is upgraded.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13610?
The severity of CVE-2026-13610 is rated at 85, indicating a high risk of exploitation.
How do I fix CVE-2026-13610?
To fix CVE-2026-13610, update the KiviCare plugin to version 4.5.2 or later.
What type of vulnerability is CVE-2026-13610?
CVE-2026-13610 is an unauthenticated privilege escalation vulnerability.
What can an attacker do with CVE-2026-13610?
An attacker can create an active, privileged clinic-staff account, gaining full access to patient records and clinic data.
Which WordPress plugin is affected by CVE-2026-13610?
The vulnerability affects the KiviCare WordPress plugin versions before 4.5.2.