CVE-2026-13610
EUVD-2026-5772513.08.2026, 06:17
The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.