What is CVE-2026-13612?
CVE-2026-13612 is a vulnerability in the KiviCare WordPress plugin before version 4.5.2. It allows authenticated patient-level users to read other patients' bills, invoices, and appointment details due to missing ownership verification on accessed records. Updating to version 4.5.2 or later is strongly recommended to prevent unauthorized access to sensitive medical records.
Azərbaycanca: CVE-2026-13612, KiviCare WordPress plaginində aşkar edilmiş zəiflikdir. 4.5.2 versiyasından əvvəlki versiyalarda autentifikasiya olunmuş xəstə səviyyəli istifadəçilər, aidiyyəti olmadıqları digər xəstələrin hesab-faktura, qəbz və görüş detallarına icazəsiz giriş əldə edə bilərlər. Bu zəiflik məxfi tibbi məlumatların ifşasına səbəb ola bilər, dərhal 4.5.2 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of the KiviCare plugin are affected by CVE-2026-13612?
This vulnerability affects all versions of the KiviCare WordPress plugin prior to version 4.5.2.
What type of data can an authenticated patient-level user access without authorization by exploiting CVE-2026-13612?
Authenticated patient-level users can gain unauthorized access to other patients' bills, invoices, and appointment details.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.