← WordPress Vulnerabilities
WordPress security by component

KiviCare – Clinic & Patient Management System (EHR)

KiviCare – Clinic & Patient Management System (EHR) is a WordPress component with 14 published CVE records in this archive. The latest tracked vulnerability was published Jul 11, 2026; the highest CVE/CNA score is 8.5.

Plugin slug: kivicare-clinic-management-system

CVE-2026-15073: KiviCare – Clinic & Patient Management System (EHR): SQL injection

KiviCare – Clinic & Patient Management System (EHR) is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 4.5.0.

PublishedJul 11, 2026
Known safe version> 4.5.0
Safe version
Jul 11, 2026 CVE-2026-15073
KiviCare – Clinic & Patient Management System (EHR): SQL injection
KiviCare – Clinic & Patient Management System (EHR) is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 4.5.0.
> 4.5.0
CVE6.5
NVDPending
Jul 11, 2026 CVE-2026-15072
KiviCare – Clinic & Patient Management System (EHR): SQL injection
KiviCare – Clinic & Patient Management System (EHR) is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 4.5.0.
> 4.5.0
CVE6.5
NVDPending
Jul 10, 2026 CVE-2026-11990
KiviCare – Clinic & Patient Management System (EHR): A security weakness
KiviCare – Clinic & Patient Management System (EHR) is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 4.4.0.
> 4.4.0
CVE5.3
NVDPending
Jun 15, 2026 CVE-2026-40792
KiviCare: A security weakness
KiviCare is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 4.2.1.
4.3.0
CVE6.3
NVDPending
May 27, 2026 CVE-2026-42735
KiviCare: Privilege escalation or authentication bypass
KiviCare is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 4.3.0.
4.4.0
CVE8.2
NVDPending
Mar 25, 2026 CVE-2026-25383
KiviCare: Cross-site scripting
KiviCare is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.6.16.
4.0.0
CVE7.1
NVDPending
Mar 25, 2026 CVE-2026-25034
KiviCare: A security weakness
KiviCare is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.6.16.
4.0.0
CVE6.5
NVDPending
Mar 18, 2026 CVE-2026-2992
KiviCare – Clinic & Patient Management System (EHR): Privilege escalation or authentication bypass
KiviCare – Clinic & Patient Management System (EHR) is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.2
NVDPending
Mar 18, 2026 CVE-2026-2991
KiviCare – Clinic & Patient Management System (EHR): Privilege escalation or authentication bypass
KiviCare – Clinic & Patient Management System (EHR) is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE7.3
NVDPending
Feb 03, 2026 CVE-2026-25022
KiviCare: SQL injection
KiviCare is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.5
NVDPending
Jan 23, 2026 CVE-2026-0927
KiviCare – Clinic & Patient Management System (EHR): Dangerous file upload
KiviCare – Clinic & Patient Management System (EHR) is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE5.3
NVDPending
Nov 21, 2025 CVE-2025-66095
KiviCare: SQL injection
KiviCare is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.5
NVDPending
Feb 28, 2025 CVE-2025-1572
KiviCare – Clinic & Patient Management System (EHR): SQL injection
KiviCare – Clinic & Patient Management System (EHR) is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE6.5
NVD8.8
Jun 08, 2024 CVE-2024-35659
KiviCare: A security weakness
KiviCare is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD8.8