What is CVE-2026-19416?
The KiviCare WordPress plugin (versions before 4.5.4) does not verify that the requesting user owns the appointment being modified, allowing authenticated patient-level users to cancel and reschedule other patients' appointments. Upgrading to version 4.5.4 or later is strongly recommended to mitigate this vulnerability.
Azərbaycanca: KiviCare WordPress plaginində (4.5.4-dən əvvəlki versiyalarda) autentifikasiya olunmuş xəstə səviyyəli istifadəçilər digər xəstələrin randevularını ləğv edə və ya dəyişdirə bilər. Plagin təsirə məruz qalan randevunun sahibini yoxlamadığı üçün bu qüsurdan istifadə etmək mümkündür. Dərhal 4.5.4 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which users can cancel other patients' appointments in the KiviCare plugin?
Authenticated patient-level users can exploit this flaw to cancel and reschedule other patients' appointments.
How can CVE-2026-19416 be fixed?
It is strongly recommended to upgrade the KiviCare plugin to version 4.5.4 or later immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.