top of page
perceptive_background_267k.jpg

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.1.2.…

Published:

17 maart 2026 om 23:00:00

Alert date:

18 maart 2026 om 17:03:14

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access, Data Breach & Exfiltration

The KiviCare Clinic & Patient Management System plugin for WordPress contains a critical authentication bypass vulnerability in versions up to 4.1.2. The patientSocialLogin() function fails to verify social provider access tokens, allowing attackers to authenticate as any patient using only an email address and arbitrary token value. This grants unauthorized access to sensitive medical records, appointments, prescriptions, and billing information, constituting a serious PII/PHI breach. The vulnerability also affects authentication cookie handling for non-patient users including administrators.

Technical details

Mitigation steps:

Affected products:

KiviCare Clinic & Patient Management System WordPress Plugin

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page