What the vulnerability does
01Description
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the `/wp-json/kivicare/v1/setup-wizard/clinic` REST API endpoint in all versions up to, and including, 4.1.2. This makes it possible for unauthenticated attackers to create a new clinic and a WordPress user with clinic admin privileges.
Explanation of Vulnerability in Simple Terms
02Summary
KiviCare versions up to 4.1.2 lack proper authorization checks, allowing unauthenticated attackers to modify data through network requests. An attacker can change records without needing valid credentials or user interaction. The vulnerability affects the clinic management system's data integrity but does not expose sensitive information or disrupt availability.
What an attacker can do
03Attacker Capabilities
Modify clinic or patient records without authentication.
Potential impact on your site
04Site Impact
Patient or clinic data can be altered by unauthorized parties, compromising record accuracy and compliance.
Conditions required to exploit
05Prerequisites
Network access to the KiviCare installation; no authentication or user interaction required.
Key dates
06Disclosure timeline
March 18, 2026
CVE published
April 8, 2026
Record updated