What is CVE-2026-15453?
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress (versions ≤4.5.1) contains an SQL Injection vulnerability via the 'searchTerm' parameter due to insufficient escaping and query preparation. This allows unauthenticated attackers to interfere with database queries. Updating to the latest plugin version is recommended.
Azərbaycanca: KiviCare – WordPress üçün klinika idarəetmə pluginində (versiya ≤4.5.1) 'searchTerm' parametri vasitəsilə SQL Injection (SQLi) zəifliyi aşkarlanıb. Bu, autentifikasiya olmamış hücumçulara verilənlər bazasına müdaxilə etməyə imkan verir. Pluginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of the KiviCare plugin are affected by the CVE-2026-15453 SQL Injection vulnerability?
The KiviCare plugin versions 4.5.1 and earlier are affected by this vulnerability.
What should be done to protect against the CVE-2026-15453 vulnerability?
To protect against this vulnerability, it is recommended to update the KiviCare plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.