PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-13610 KiviCare CVE debrief

The KiviCare WordPress plugin before 4.5.2 has a critical vulnerability in its unauthenticated registration endpoint. This allows unauthenticated attackers to create active, privileged clinic-staff (doctor) accounts with full access to patient records, billing, and clinic data. The vulnerability has a CVSS score of 7.5, indicating HIGH severity. Administrators and users of the KiviCare WordPress plugin should be aware of this vulnerability and take necessary actions to mitigate it. The CVE record was published on 2026-08-13T06:17:37.780Z and has not been modified since then. Evidence is based on a single source reference from WPScan.

Vendor
KiviCare
Product
KiviCare WordPress plugin
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-13
Original CVE updated
2026-08-26
Advisory published
2026-08-13
Advisory updated
2026-08-26

Who should care

Administrators and users of the KiviCare WordPress plugin, particularly those with patient records, billing, and clinic data, should be aware of this vulnerability and take necessary actions to mitigate it. This includes reviewing and restricting roles assignable through the registration endpoint, updating the plugin to version 4.5.2 or later, and monitoring for suspicious account creation activity on the WordPress site. Additionally, implementing additional authentication and authorization controls for the registration endpoint can help prevent exploitation of this vulnerability. Security teams and vulnerability management teams should also be aware of this vulnerability and prioritize remediation efforts accordingly. Operators of WordPress sites using the KiviCare plugin should review their current configurations and ensure that they are not exposed to this vulnerability. Vulnerability management teams should track exceptions and retest remediated assets to ensure that the vulnerability is properly mitigated. IT security teams should also review compensating controls for exposed systems while remediation is scheduled and verified. This vulnerability affects KiviCare WordPress plugin deployments, and operators should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Security teams should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Monitoring and detection teams should check relevant monitoring, detection, and logs for exposed assets that need extra review. Asset inventory teams should track affected assets and prioritize remediation efforts accordingly. Rollback/change windows teams should review their current change management processes to ensure that remediation efforts are properly prioritized and implemented. Source tracking teams should track the source of the vulnerability and any related updates or advisories. Compensating controls teams should review their current compensating controls and ensure that they are effective in mitigating this vulnerability. Exposure review teams should review their current exposure to this vulnerability,

Technical summary

The KiviCare WordPress plugin before 4.5.2 has a vulnerability in its unauthenticated registration endpoint, allowing attackers to create active, privileged clinic-staff (doctor) accounts with full access to patient records, billing, and clinic data. The CVSS score for this vulnerability is 7.5, indicating HIGH severity. This vulnerability can be exploited by unauthenticated attackers, which increases the risk of patient data exposure and potential misuse. The vulnerability is considered HIGH severity due to the ease of exploitation and potential impact on patient data.

Defensive priority

CVE-2026-13610 has a CVSS score of 7.5 and is considered HIGH severity. Unauthenticated attackers can create a privileged clinic-staff account with full access to patient records, billing, and clinic data through the KiviCare WordPress plugin's registration endpoint.

Recommended defensive actions

  • Review and restrict roles assignable through the KiviCare WordPress plugin's registration endpoint.
  • Update the KiviCare WordPress plugin to version 4.5.2 or later.
  • Monitor for suspicious account creation activity on the WordPress site.
  • Implement additional authentication and authorization controls for the registration endpoint.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The KiviCare WordPress plugin before 4.5.2 does not restrict roles assignable through its unauthenticated registration endpoint. This allows unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing, and clinic data. Evidence is based on a single source reference from WPScan.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-13610 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-13610

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-13610 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-13610

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.