Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesKiviCare

KiviCare vulnerabilities

KiviCare has 22 known vulnerabilities in this database. The most recent published record is dated 1 Sep 2026.

Known vulnerabilities
22
Active installs
1,000+
Latest version
4.5.6
Last updated
29 Sep 2026
Most recent
1 Sep 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Sensitive data exposure
CVE-2026-13611
Medium 5.3Before 4.5.5Fixed in 4.5.51 Sep 2026
Broken access control
CVE-2026-19417
Medium 6.5Before 4.5.4Fixed in 4.5.419 Aug 2026
Broken access control
CVE-2026-19416
Medium 4.3Before 4.5.4Fixed in 4.5.419 Aug 2026
SQL injection
CVE-2026-15453
Medium 6.5Up to 4.5.1Fixed in a later version (latest 4.5.6)15 Aug 2026
Privilege escalation
CVE-2026-13610
High 7.5Before 4.5.2Fixed in 4.5.213 Aug 2026
SQL injection
CVE-2026-13613
High 8.8Before 4.5.2Fixed in 4.5.212 Aug 2026
Broken access control
CVE-2026-13612
Medium 4.3Before 4.5.2Fixed in 4.5.212 Aug 2026
SQL injection
CVE-2026-15073
Medium 6.5Up to 4.5.0Fixed in a later version (latest 4.5.6)11 Jul 2026
SQL injection
CVE-2026-15072
Medium 6.5Up to 4.5.0Fixed in a later version (latest 4.5.6)11 Jul 2026
Broken access control
CVE-2026-11990
Medium 5.3Up to 4.4.0Fixed in a later version (latest 4.5.6)10 Jul 2026
Authentication bypass
CVE-2026-2991
High 7.3Up to 4.1.2Fixed in a later version (latest 4.5.6)18 Mar 2026
Privilege escalation
CVE-2026-2992
High 8.2Up to 4.1.2Fixed in a later version (latest 4.5.6)18 Mar 2026
Arbitrary file upload
CVE-2026-0927
Medium 5.3Up to 3.6.15Fixed in a later version (latest 4.5.6)23 Jan 2026
SQL injection
CVE-2025-1572
Medium 6.5Before 3.6.8Fixed in 3.6.828 Feb 2025
SQL injection
CVE-2024-11730
Medium 6.5Before 3.6.5Fixed in 3.6.56 Dec 2024
SQL injection
CVE-2024-11729
Medium 6.5Up to 3.6.5Fixed in a later version (latest 4.5.6)6 Dec 2024
SQL injection
CVE-2024-11728
High 7.5Up to 3.6.5Fixed in a later version (latest 4.5.6)6 Dec 2024
Cross-site scripting (XSS)
CVE-2023-2624
Medium 6.1Before 3.2.1Fixed in 3.2.127 Jun 2023
Cross-site request forgery (CSRF)
CVE-2023-2627
Medium 4.3Before 3.2.1Fixed in 3.2.127 Jun 2023
Cross-site request forgery (CSRF)
CVE-2023-2628
High 8.8Before 3.2.1Fixed in 3.2.127 Jun 2023
Security weakness
CVE-2023-2623
Medium 6.5Before 3.2.1Fixed in 3.2.127 Jun 2023
SQL injection
CVE-2022-0786
Critical 9.8Before 2.3.9Fixed in 2.3.913 Jun 2022
Read the published descriptions
CVE-2026-13611, 1 Sep 2026
The KiviCare WordPress plugin before 4.5.5 does not perform authorization checks on some of its REST endpoints, allowing unauthenticated attackers to disclose the patient roster and, when a payment gateway is configured, the payment gateway secret key. CVE record
CVE-2026-19417, 19 Aug 2026
The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media file being served, allowing authenticated patient-level users to download any file in the media library, including other patients' uploaded medical reports. CVE record
CVE-2026-19416, 19 Aug 2026
The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user owns the appointment being modified, allowing authenticated patient-level users to cancel and reschedule other patients' appointments. CVE record
CVE-2026-15453, 15 Aug 2026
The KiviCare - Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'searchTerm' parameter in all versions up to, and including, 4.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires a KiviCare custom role with the 'settings_view' permission (e.g., Doctor or Receptionist), meaning standard WordPress subscribers cannot exploit this without a KiviCare-assigned role. CVE record
CVE-2026-13610, 13 Aug 2026
The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data. CVE record
CVE-2026-13613, 12 Aug 2026
The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using them in a SQL query, allowing authenticated users with a clinic staff-level role to perform SQL injection. CVE record
CVE-2026-13612, 12 Aug 2026
The KiviCare WordPress plugin before 4.5.2 does not verify that the requesting user owns the records being accessed, allowing authenticated patient-level users to read other patients' bills, invoices and appointment details. CVE record
CVE-2026-15073, 11 Jul 2026
The KiviCare - Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 4.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Doctor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires a KiviCare Doctor, Receptionist, or Clinic Admin role at minimum, as the vulnerable REST endpoint is restricted to authenticated users with custom plugin-level access. CVE record
CVE-2026-15072, 11 Jul 2026
The KiviCare - Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 4.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with doctor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This requires that the attacker hold at minimum a KiviCare Doctor-level account, or a Receptionist or Clinic Admin role that grants the doctor_session_list capability. CVE record
CVE-2026-11990, 10 Jul 2026
The KiviCare - Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.4.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark arbitrary pending appointments as Confirmed and forge an associated completed payment record in wp_kc_payments_appointment_mappings using an attacker-supplied payment ID, bypassing payment entirely. This exploit is achievable on a default installation because the gateway resolution logic returns all registered gateways regardless of admin-enabled status, making the manual (KCPayLater) gateway always selectable. CVE record
CVE-2026-2991, 18 Mar 2026
The KiviCare - Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.1.2. This is due to the `patientSocialLogin()` function not verifying the social provider access token before authenticating a user. This makes it possible for unauthenticated attackers to log in as any patient registered on the system by providing only their email address and an arbitrary value for the access token, bypassing all credential verification. The attacker gains access to sensitive medical records, appointments, prescriptions, and billing information (PII/PHI breach). Additionally, authentication cookies are set before the role check, meaning the auth cookies for non-patient users (including administrators) are also set in the HTTP response headers, even though a 403 response is returned. CVE record
CVE-2026-2992, 18 Mar 2026
The KiviCare - Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the `/wp-json/kivicare/v1/setup-wizard/clinic` REST API endpoint in all versions up to, and including, 4.1.2. This makes it possible for unauthenticated attackers to create a new clinic and a WordPress user with clinic admin privileges. CVE record
CVE-2026-0927, 23 Jan 2026
The KiviCare - Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization checks in the uploadMedicalReport() function in all versions up to, and including, 3.6.15. This makes it possible for unauthenticated attackers to upload text files and PDF documents to the affected site's server which may be leveraged for further attacks such as hosting malicious content or phishing pages via PDF files. CVE record
CVE-2025-1572, 28 Feb 2025
The KiviCare - Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the ‘u_id’ parameter in all versions up to, and including, 3.6.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with doctor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2024-11730, 6 Dec 2024
The KiviCare - Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'sort[]' parameter of the static_data_list AJAX action in all versions up to, and including, 3.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with doctor/receptionist-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2024-11729, 6 Dec 2024
The KiviCare - Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'service_list[0][service_id]' parameter of the get_widget_payment_options AJAX action in all versions up to, and including, 3.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2024-11728, 6 Dec 2024
The KiviCare - Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'visit_type[service_id]' parameter of the tax_calculated_data AJAX action in all versions up to, and including, 3.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2023-2624, 27 Jun 2023
The KiviCare WordPress plugin before 3.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrator CVE record
CVE-2023-2627, 27 Jun 2023
The KiviCare WordPress plugin before 3.2.1 does not have proper CSRF and authorisation checks in various AJAX actions, allowing any authenticated users, such as subscriber to call them. Attacks include but are not limited to: Add arbitrary Clinic Admin/Doctors/etc and update plugin's settings CVE record
CVE-2023-2628, 27 Jun 2023
The KiviCare WordPress plugin before 3.2.1 does not have CSRF checks (either flawed or missing completely) in various AJAX actions, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks. This includes, but is not limited to: Delete arbitrary appointments/medical records/etc, create/update various users (patients, doctors etc) CVE record
CVE-2023-2623, 27 Jun 2023
The KiviCare WordPress plugin before 3.2.1 does not restrict the information returned in a response and returns all user data, allowing low privilege users such as subscriber to retrieve sensitive information such as the user email and hashed password of other users CVE record
CVE-2022-0786, 13 Jun 2022
The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via the ajax_post AJAX action with the get_doctor_details route, leading to SQL Injections exploitable by unauthenticated users CVE record

What to do if you run KiviCare

If you run KiviCare, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new KiviCare vulnerabilities

Free. We email you when a new vulnerability is published for KiviCare, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support