The KiviCare – Clinic & Patient Management System (EHR)...
High severity
Unreviewed
Published
Mar 18, 2026
to the GitHub Advisory Database
•
Updated Mar 18, 2026
Description
Published by the National Vulnerability Database
Mar 18, 2026
Published to the GitHub Advisory Database
Mar 18, 2026
Last updated
Mar 18, 2026
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the
/wp-json/kivicare/v1/setup-wizard/clinicREST API endpoint in all versions up to, and including, 4.1.2. This makes it possible for unauthenticated attackers to create a new clinic and a WordPress user with clinic admin privileges.References