CVE-2026-73188 HIGH

CVE-2026-73188: WordPress KiviCare plugin <= 4.5.1 - Sensitive Data Exposure vulnerability

Vendor Iqonic Design
Product KiviCare
Weakness CWE-288
Published August 13, 2026
Last update August 13, 2026

CVSS base score

7.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

Unauthenticated Sensitive Data Exposure in KiviCare <= 4.5.1 versions.

Explanation of Vulnerability in Simple Terms

02Summary

KiviCare versions up to 4.5.1 contain an authentication bypass vulnerability that allows attackers to access the system without valid credentials. The flaw exists in an alternate authentication path or channel, enabling unauthorized access to sensitive data. No user interaction or special privileges are required to exploit this issue.

What an attacker can do

03Attacker Capabilities

Access the system and read sensitive data without providing valid login credentials.

Potential impact on your site

04Site Impact

Unauthorized users can view confidential patient or business data stored in KiviCare without logging in.

Conditions required to exploit

05Prerequisites

Network access to the KiviCare installation; no authentication or user interaction required.

Key dates

06Disclosure timeline

August 13, 2026 CVE published
August 13, 2026 Record updated

Related vulnerabilities

08Related CVE