CVE-2026-13613: KiviCare < 4.5.2 - Doctor/Receptionist+ SQL Injection via settings/listing REST Endpoint
Published Aug 12, 2026
·Updated
The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using them in a SQL query, allowing authenticated users with a clinic staff-level role to perform SQL injection.
Affected Software
1 affected component
KiviCare WordPress plugin<4.5.2
Event History
Aug 12, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-13613?
The severity of CVE-2026-13613 is rated at 55, indicating a moderate risk level.
2
How do I fix CVE-2026-13613?
To fix CVE-2026-13613, update the KiviCare WordPress plugin to version 4.5.2 or later.
3
Who is affected by CVE-2026-13613?
CVE-2026-13613 affects authenticated users with a clinic staff-level role in the KiviCare WordPress plugin version prior to 4.5.2.
4
What type of vulnerability is CVE-2026-13613?
CVE-2026-13613 is classified as an SQL Injection vulnerability.
5
When was CVE-2026-13613 published?
CVE-2026-13613 was published on August 12, 2026.