Sploitus

CVE-2026-13610

1 known exploit for CVE-2026-13610

The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data.

EPSS
0.1% (5th percentile)
NVD status
Received
Published
2026-08-13
CVE-2026-13610 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2026-13610

Proof-of-concept code and exploit modules indexed by Sploitus