PatchSiren cyber security CVE debrief
CVE-2026-13610 KiviCare CVE debrief
The KiviCare WordPress plugin before 4.5.2 has a critical vulnerability in its unauthenticated registration endpoint. This allows unauthenticated attackers to create active, privileged clinic-staff (doctor) accounts with full access to patient records, billing, and clinic data. The vulnerability has a CVSS score of 7.5, indicating HIGH severity. Administrators and users of the KiviCare WordPress plugin should be aware of this vulnerability and take necessary actions to mitigate it. The CVE record was published on 2026-08-13T06:17:37.780Z and has not been modified since then. Evidence is based on a single source reference from WPScan.
- Vendor
- KiviCare
- Product
- KiviCare WordPress plugin
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-13
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-13
- Advisory updated
- 2026-08-26
Who should care
Administrators and users of the KiviCare WordPress plugin, particularly those with patient records, billing, and clinic data, should be aware of this vulnerability and take necessary actions to mitigate it. This includes reviewing and restricting roles assignable through the registration endpoint, updating the plugin to version 4.5.2 or later, and monitoring for suspicious account creation activity on the WordPress site. Additionally, implementing additional authentication and authorization controls for the registration endpoint can help prevent exploitation of this vulnerability. Security teams and vulnerability management teams should also be aware of this vulnerability and prioritize remediation efforts accordingly. Operators of WordPress sites using the KiviCare plugin should review their current configurations and ensure that they are not exposed to this vulnerability. Vulnerability management teams should track exceptions and retest remediated assets to ensure that the vulnerability is properly mitigated. IT security teams should also review compensating controls for exposed systems while remediation is scheduled and verified. This vulnerability affects KiviCare WordPress plugin deployments, and operators should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Security teams should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Monitoring and detection teams should check relevant monitoring, detection, and logs for exposed assets that need extra review. Asset inventory teams should track affected assets and prioritize remediation efforts accordingly. Rollback/change windows teams should review their current change management processes to ensure that remediation efforts are properly prioritized and implemented. Source tracking teams should track the source of the vulnerability and any related updates or advisories. Compensating controls teams should review their current compensating controls and ensure that they are effective in mitigating this vulnerability. Exposure review teams should review their current exposure to this vulnerability,
Technical summary
The KiviCare WordPress plugin before 4.5.2 has a vulnerability in its unauthenticated registration endpoint, allowing attackers to create active, privileged clinic-staff (doctor) accounts with full access to patient records, billing, and clinic data. The CVSS score for this vulnerability is 7.5, indicating HIGH severity. This vulnerability can be exploited by unauthenticated attackers, which increases the risk of patient data exposure and potential misuse. The vulnerability is considered HIGH severity due to the ease of exploitation and potential impact on patient data.
Defensive priority
CVE-2026-13610 has a CVSS score of 7.5 and is considered HIGH severity. Unauthenticated attackers can create a privileged clinic-staff account with full access to patient records, billing, and clinic data through the KiviCare WordPress plugin's registration endpoint.
Recommended defensive actions
- Review and restrict roles assignable through the KiviCare WordPress plugin's registration endpoint.
- Update the KiviCare WordPress plugin to version 4.5.2 or later.
- Monitor for suspicious account creation activity on the WordPress site.
- Implement additional authentication and authorization controls for the registration endpoint.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The KiviCare WordPress plugin before 4.5.2 does not restrict roles assignable through its unauthenticated registration endpoint. This allows unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing, and clinic data. Evidence is based on a single source reference from WPScan.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-13610 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-13610
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-13610 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-13610
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/24951a75-46e7-44f9-947b-070ca2f2b244/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.