WordPress Plugin Vulnerabilities
KiviCare – Clinic & Patient Management System (EHR) < 4.5.5 - Unauthenticated Patient Data Disclosure
Description
The plugin does not perform authorization checks on some of its REST endpoints, allowing unauthenticated attackers to disclose the patient roster and, when a payment gateway is configured, the payment gateway secret key.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Sai Praneeth Koti
Submitter
Sai Praneeth Koti
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-08-28 (about 4 days ago)
Added
2026-08-28 (about 3 days ago)
Last Updated
2026-08-28 (about 3 days ago)