WordPress Plugin Vulnerabilities

KiviCare – Clinic & Patient Management System (EHR) < 4.5.5 - Unauthenticated Patient Data Disclosure

Description

The plugin does not perform authorization checks on some of its REST endpoints, allowing unauthenticated attackers to disclose the patient roster and, when a payment gateway is configured, the payment gateway secret key.

Proof of Concept

Affects Plugins

References

Miscellaneous

Original Researcher
Sai Praneeth Koti
Submitter
Sai Praneeth Koti
Verified
Yes

Timeline

Publicly Published
2026-08-28 (about 4 days ago)
Added
2026-08-28 (about 3 days ago)
Last Updated
2026-08-28 (about 3 days ago)

Other