HIGH
KiviCare
CVE published 2026-08-13
CVE-2026-13610
The KiviCare WordPress plugin before 4.5.2 has a critical vulnerability in its unauthenticated registration endpoint. This allows unauthenticated attackers to create active, privileged clinic-staff (doctor) accounts with full access to patient records, billing, and clinic data. The vulnerability has a CVSS score of 7.5, indicating HIGH severity. Administrators and users of the KiviCare WordPress plugin sh [truncated]