CVE-2026-25034: WordPress KiviCare plugin <= 3.6.16 - Broken Access Control vulnerability
Published Mar 25, 2026
·Updated
Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects KiviCare: from n/a through <= 3.6.16.
Affected Software
1 affected component
Iqonic Design KiviCare (WordPress plugin)<=3.6.16
Event History
Mar 25, 2026
CVE Published
via MITRE·04:14 PM
Data Sourced
via MITRE·04:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-25034?
CVE-2026-25034 is classified as a Broken Access Control vulnerability.
2
How do I fix CVE-2026-25034?
To fix CVE-2026-25034, update the KiviCare plugin to version 3.6.17 or later.
3
What versions are affected by CVE-2026-25034?
CVE-2026-25034 affects KiviCare plugin versions up to and including 3.6.16.
4
What is the impact of exploiting CVE-2026-25034?
Exploiting CVE-2026-25034 allows unauthorized access due to insecure access control configurations.
5
Who is the vendor for the affected product in CVE-2026-25034?
The vendor for the affected product in CVE-2026-25034 is Iqonic Design.