Insecure Direct Object Reference in KiviCare by KiviSolutions
CVE-2026-40792

6.3MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
15 June 2026

What is CVE-2026-40792?

The KiviCare plugin, up to version 4.2.1, contains a vulnerability due to insecure direct object references (IDOR). This weakness allows unauthorized users to access sensitive data or perform actions beyond their intended permissions, potentially compromising the integrity and confidentiality of user information. It is crucial for administrators to apply mitigations to safeguard against exploitation of this flaw.

Affected Version(s)

KiviCare <= 4.2.1

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jakub Herman | Patchstack Bug Bounty Program
.