Authentication Bypass in KiviCare WordPress Plugin Allows Unauthorized Account Creation
CVE-2026-13610
Currently unrated
Key Information:
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-13610?
The KiviCare WordPress plugin prior to version 4.5.2 is vulnerable due to a lack of restrictions on role assignments via its unauthenticated registration endpoint. This flaw enables attackers to create active, privileged accounts, such as clinic staff (doctors), granting them full access to sensitive information including patient records, billing details, and overall clinic data.
Affected Version(s)
KiviCare 0 < 4.5.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.