What is CVE-2026-13610?
This vulnerability in the KiviCare WordPress plugin before version 4.5.2 allows unauthenticated attackers to register a privileged clinic-staff account via an unrestricted registration endpoint. This grants full access to patient records, billing, and clinic data. Updating to the latest plugin version is strongly recommended.
Azərbaycanca: Bu zəiflik KiviCare WordPress plaginində 4.5.2 versiyasından əvvəlki versiyalarda aşkar edilib. O, autentifikasiya olunmamış qeydiyyat endpoint-i vasitəsilə icazəsiz hücumçulara yüksək səlahiyyətli klinika işçisi hesabı yaratmağa imkan verir. Plaginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which versions of the KiviCare plugin are affected by CVE-2026-13610?
This vulnerability affects versions of the KiviCare WordPress plugin before 4.5.2.
What can an attacker achieve by exploiting CVE-2026-13610?
An unauthenticated attacker can register a privileged clinic-staff account via the registration endpoint, granting full access to patient records, billing, and clinic data.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.