CVE-2026-13610 UNKNOWN

CVE-2026-13610

Published: 2026-08-13

Description

The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…