CVE-2026-13611: KiviCare – Clinic & Patient Management System (EHR) < 4.5.5 - Unauthenticated Patient Data Disclosure
The KiviCare WordPress plugin before 4.5.5 does not perform authorization checks on some of its REST endpoints, allowing unauthenticated attackers to disclose the patient roster and, when a payment gateway is configured, the payment gateway secret key.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
KiviCare – Clinic & Patient Management System (EHR) WordPress pluginto a version that resolves this vulnerability.Fixed in 4.5.5 - Operational
If a payment gateway is configured and the gateway secret key may have been disclosed via the vulnerable REST endpoints, rotate/revokes the payment gateway secret key after upgrading to KiviCare plugin 4.5.5.
Event History
Frequently Asked Questions
Who is exposed to this issue?
WordPress sites using the KiviCare plugin at versions before 4.5.5 are affected. Exposure includes patient roster disclosure; sites with a payment gateway configured may also expose that gateway's secret key.
What does an attacker need to exploit it?
An attacker can exploit the affected REST endpoints remotely without authentication, privileges, or user interaction.
Does a payment gateway need to be configured for the secret key to be exposed?
Yes. The payment gateway secret key is disclosed only when a payment gateway is configured; the patient roster disclosure does not state that such configuration is required.