What is CVE-2026-13613?
CVE-2026-13613 is an SQL injection vulnerability in the KiviCare WordPress plugin before version 4.5.2. It stems from improper sanitization and escaping of user-supplied parameters, allowing authenticated users with clinic staff-level roles to interfere with database queries. Affected systems should be updated to the latest plugin version immediately.
Azərbaycanca: CVE-2026-13613 KiviCare WordPress plaginində (4.5.2-dən əvvəlki versiyalar) aşkar edilmiş SQL inyeksiya zəifliyidir. Bu zəiflik istifadəçi tərəfindən təqdim edilən parametrlərin düzgün təmizlənməməsi səbəbindən yaranır və klinika işçisi səviyyəsində autentifikasiya olunmuş istifadəçilərə verilənlər bazasına müdaxilə etməyə imkan verir. Plagindən istifadə olunan sistemlərdə dərhal ən son versiyaya yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of the KiviCare plugin are affected by CVE-2026-13613?
CVE-2026-13613 affects versions of the KiviCare WordPress plugin prior to 4.5.2.
What level of authentication is required for an attacker to exploit CVE-2026-13613?
To exploit this vulnerability, an attacker must be authenticated with clinic staff-level roles.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.