HomeWordPress vulnerabilitiesKiviCare
KiviCare vulnerabilities
KiviCare has 22 known vulnerabilities in this database. The most recent published record is dated 1 Sep 2026.
- Known vulnerabilities
- 22
- Active installs
- 1,000+
- Latest version
- 4.5.6
- Last updated
- 29 Sep 2026
- Most recent
- 1 Sep 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Sensitive data exposure CVE-2026-13611 | Medium 5.3 | Before 4.5.5 | Fixed in 4.5.5 | 1 Sep 2026 |
| Broken access control CVE-2026-19417 | Medium 6.5 | Before 4.5.4 | Fixed in 4.5.4 | 19 Aug 2026 |
| Broken access control CVE-2026-19416 | Medium 4.3 | Before 4.5.4 | Fixed in 4.5.4 | 19 Aug 2026 |
| SQL injection CVE-2026-15453 | Medium 6.5 | Up to 4.5.1 | Fixed in a later version (latest 4.5.6) | 15 Aug 2026 |
| Privilege escalation CVE-2026-13610 | High 7.5 | Before 4.5.2 | Fixed in 4.5.2 | 13 Aug 2026 |
| SQL injection CVE-2026-13613 | High 8.8 | Before 4.5.2 | Fixed in 4.5.2 | 12 Aug 2026 |
| Broken access control CVE-2026-13612 | Medium 4.3 | Before 4.5.2 | Fixed in 4.5.2 | 12 Aug 2026 |
| SQL injection CVE-2026-15073 | Medium 6.5 | Up to 4.5.0 | Fixed in a later version (latest 4.5.6) | 11 Jul 2026 |
| SQL injection CVE-2026-15072 | Medium 6.5 | Up to 4.5.0 | Fixed in a later version (latest 4.5.6) | 11 Jul 2026 |
| Broken access control CVE-2026-11990 | Medium 5.3 | Up to 4.4.0 | Fixed in a later version (latest 4.5.6) | 10 Jul 2026 |
| Authentication bypass CVE-2026-2991 | High 7.3 | Up to 4.1.2 | Fixed in a later version (latest 4.5.6) | 18 Mar 2026 |
| Privilege escalation CVE-2026-2992 | High 8.2 | Up to 4.1.2 | Fixed in a later version (latest 4.5.6) | 18 Mar 2026 |
| Arbitrary file upload CVE-2026-0927 | Medium 5.3 | Up to 3.6.15 | Fixed in a later version (latest 4.5.6) | 23 Jan 2026 |
| SQL injection CVE-2025-1572 | Medium 6.5 | Before 3.6.8 | Fixed in 3.6.8 | 28 Feb 2025 |
| SQL injection CVE-2024-11730 | Medium 6.5 | Before 3.6.5 | Fixed in 3.6.5 | 6 Dec 2024 |
| SQL injection CVE-2024-11729 | Medium 6.5 | Up to 3.6.5 | Fixed in a later version (latest 4.5.6) | 6 Dec 2024 |
| SQL injection CVE-2024-11728 | High 7.5 | Up to 3.6.5 | Fixed in a later version (latest 4.5.6) | 6 Dec 2024 |
| Cross-site scripting (XSS) CVE-2023-2624 | Medium 6.1 | Before 3.2.1 | Fixed in 3.2.1 | 27 Jun 2023 |
| Cross-site request forgery (CSRF) CVE-2023-2627 | Medium 4.3 | Before 3.2.1 | Fixed in 3.2.1 | 27 Jun 2023 |
| Cross-site request forgery (CSRF) CVE-2023-2628 | High 8.8 | Before 3.2.1 | Fixed in 3.2.1 | 27 Jun 2023 |
| Security weakness CVE-2023-2623 | Medium 6.5 | Before 3.2.1 | Fixed in 3.2.1 | 27 Jun 2023 |
| SQL injection CVE-2022-0786 | Critical 9.8 | Before 2.3.9 | Fixed in 2.3.9 | 13 Jun 2022 |
Read the published descriptions
- CVE-2026-13611, 1 Sep 2026
- The KiviCare WordPress plugin before 4.5.5 does not perform authorization checks on some of its REST endpoints, allowing unauthenticated attackers to disclose the patient roster and, when a payment gateway is configured, the payment gateway secret key. CVE record
- CVE-2026-19417, 19 Aug 2026
- The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media file being served, allowing authenticated patient-level users to download any file in the media library, including other patients' uploaded medical reports. CVE record
- CVE-2026-19416, 19 Aug 2026
- The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user owns the appointment being modified, allowing authenticated patient-level users to cancel and reschedule other patients' appointments. CVE record
- CVE-2026-15453, 15 Aug 2026
- The KiviCare - Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'searchTerm' parameter in all versions up to, and including, 4.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires a KiviCare custom role with the 'settings_view' permission (e.g., Doctor or Receptionist), meaning standard WordPress subscribers cannot exploit this without a KiviCare-assigned role. CVE record
- CVE-2026-13610, 13 Aug 2026
- The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data. CVE record
- CVE-2026-13613, 12 Aug 2026
- The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using them in a SQL query, allowing authenticated users with a clinic staff-level role to perform SQL injection. CVE record
- CVE-2026-13612, 12 Aug 2026
- The KiviCare WordPress plugin before 4.5.2 does not verify that the requesting user owns the records being accessed, allowing authenticated patient-level users to read other patients' bills, invoices and appointment details. CVE record
- CVE-2026-15073, 11 Jul 2026
- The KiviCare - Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 4.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Doctor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires a KiviCare Doctor, Receptionist, or Clinic Admin role at minimum, as the vulnerable REST endpoint is restricted to authenticated users with custom plugin-level access. CVE record
- CVE-2026-15072, 11 Jul 2026
- The KiviCare - Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 4.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with doctor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This requires that the attacker hold at minimum a KiviCare Doctor-level account, or a Receptionist or Clinic Admin role that grants the doctor_session_list capability. CVE record
- CVE-2026-11990, 10 Jul 2026
- The KiviCare - Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.4.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark arbitrary pending appointments as Confirmed and forge an associated completed payment record in wp_kc_payments_appointment_mappings using an attacker-supplied payment ID, bypassing payment entirely. This exploit is achievable on a default installation because the gateway resolution logic returns all registered gateways regardless of admin-enabled status, making the manual (KCPayLater) gateway always selectable. CVE record
- CVE-2026-2991, 18 Mar 2026
- The KiviCare - Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.1.2. This is due to the `patientSocialLogin()` function not verifying the social provider access token before authenticating a user. This makes it possible for unauthenticated attackers to log in as any patient registered on the system by providing only their email address and an arbitrary value for the access token, bypassing all credential verification. The attacker gains access to sensitive medical records, appointments, prescriptions, and billing information (PII/PHI breach). Additionally, authentication cookies are set before the role check, meaning the auth cookies for non-patient users (including administrators) are also set in the HTTP response headers, even though a 403 response is returned. CVE record
- CVE-2026-2992, 18 Mar 2026
- The KiviCare - Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the `/wp-json/kivicare/v1/setup-wizard/clinic` REST API endpoint in all versions up to, and including, 4.1.2. This makes it possible for unauthenticated attackers to create a new clinic and a WordPress user with clinic admin privileges. CVE record
- CVE-2026-0927, 23 Jan 2026
- The KiviCare - Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization checks in the uploadMedicalReport() function in all versions up to, and including, 3.6.15. This makes it possible for unauthenticated attackers to upload text files and PDF documents to the affected site's server which may be leveraged for further attacks such as hosting malicious content or phishing pages via PDF files. CVE record
- CVE-2025-1572, 28 Feb 2025
- The KiviCare - Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the ‘u_id’ parameter in all versions up to, and including, 3.6.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with doctor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2024-11730, 6 Dec 2024
- The KiviCare - Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'sort[]' parameter of the static_data_list AJAX action in all versions up to, and including, 3.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with doctor/receptionist-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2024-11729, 6 Dec 2024
- The KiviCare - Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'service_list[0][service_id]' parameter of the get_widget_payment_options AJAX action in all versions up to, and including, 3.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2024-11728, 6 Dec 2024
- The KiviCare - Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'visit_type[service_id]' parameter of the tax_calculated_data AJAX action in all versions up to, and including, 3.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2023-2624, 27 Jun 2023
- The KiviCare WordPress plugin before 3.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrator CVE record
- CVE-2023-2627, 27 Jun 2023
- The KiviCare WordPress plugin before 3.2.1 does not have proper CSRF and authorisation checks in various AJAX actions, allowing any authenticated users, such as subscriber to call them. Attacks include but are not limited to: Add arbitrary Clinic Admin/Doctors/etc and update plugin's settings CVE record
- CVE-2023-2628, 27 Jun 2023
- The KiviCare WordPress plugin before 3.2.1 does not have CSRF checks (either flawed or missing completely) in various AJAX actions, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks. This includes, but is not limited to: Delete arbitrary appointments/medical records/etc, create/update various users (patients, doctors etc) CVE record
- CVE-2023-2623, 27 Jun 2023
- The KiviCare WordPress plugin before 3.2.1 does not restrict the information returned in a response and returns all user data, allowing low privilege users such as subscriber to retrieve sensitive information such as the user email and hashed password of other users CVE record
- CVE-2022-0786, 13 Jun 2022
- The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via the ajax_post AJAX action with the get_doctor_details route, leading to SQL Injections exploitable by unauthenticated users CVE record
What to do if you run KiviCare
If you run KiviCare, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new KiviCare vulnerabilities
Free. We email you when a new vulnerability is published for KiviCare, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.