PatchSiren

KiviCare CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH KiviCare CVE published 2026-08-13

CVE-2026-13610

The KiviCare WordPress plugin before 4.5.2 has a critical vulnerability in its unauthenticated registration endpoint. This allows unauthenticated attackers to create active, privileged clinic-staff (doctor) accounts with full access to patient records, billing, and clinic data. The vulnerability has a CVSS score of 7.5, indicating HIGH severity. Administrators and users of the KiviCare WordPress plugin sh [truncated]