CVE-2026-13611

The KiviCare WordPress plugin before 4.5.5 does not perform authorization checks on some of its REST endpoints, allowing unauthenticated attackers to disclose the patient roster and, when a payment gateway is configured, the payment gateway secret key.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-01 08:17

Updated : 2026-09-01 20:50


NVD link : CVE-2026-13611

Mitre link : CVE-2026-13611

CVE.ORG link : CVE-2026-13611


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-862

Missing Authorization