Loading market data...
← Back to CVE feed

CVE-2026-13610

UNKNOWN View on NVD ↗

Description

The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data.

Published: Aug 13, 2026 06:17 UTC Modified: Aug 13, 2026 06:17 UTC