CVE-2026-42735: WordPress KiviCare plugin <= 4.3.0 - Broken Authentication vulnerability
Published May 27, 2026
·Updated
Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Password Recovery Exploitation.This issue affects KiviCare: from n/a through <= 4.3.0.
Affected Software
1 affected component
Iqonic Design KiviCare WordPress plugin<=4.3.0
Event History
May 27, 2026
CVE Published
via MITRE·09:49 AM
Data Sourced
via MITRE·09:49 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-42735?
The severity of CVE-2026-42735 is high with a score of 8.2.
2
How do I fix CVE-2026-42735?
To fix CVE-2026-42735, update the KiviCare plugin to a version greater than 4.3.0.
3
What type of vulnerability is CVE-2026-42735?
CVE-2026-42735 is a Broken Authentication vulnerability that allows for exploitation of password recovery features.
4
Which software is affected by CVE-2026-42735?
The affected software is the Iqonic Design KiviCare WordPress plugin, specifically versions n/a through 4.3.0.
5
What impact does CVE-2026-42735 have on security?
CVE-2026-42735 can potentially allow unauthorized access to accounts due to credential exploitation.