SQL Injection Vulnerability in KiviCare Clinic & Patient Management System by WordPress
CVE-2025-1572

8.8HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
28 February 2025

Summary

The KiviCare – Clinic & Patient Management System plugin for WordPress is susceptible to an SQL Injection vulnerability through the 'u_id' parameter. This issue arises from inadequate input escaping and insufficient SQL query preparation. Authenticated users with doctor-level access or higher can exploit this vulnerability to inject unauthorized SQL queries into existing ones, potentially leading to unauthorized access to sensitive database information.

Affected Version(s)

KiviCare – Clinic & Patient Management System (EHR) * <= 3.6.7

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

wesley
.