CVE-2026-13610

CVE-2026-13610CVE-2026-13610

Description

The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data.

Scoring

Last modified2026-08-13
Sourced from NVD. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.