Unauthenticated Privilege Escalation in KiviCare WordPress Plugin
The KiviCare WordPress plugin (<= 4.5.1) is vulnerable to unauthenticated account creation via its REST API, allowing attackers to escalate privileges to doctor or receptionist roles and access sensitive patient PHI.
CVE search metadata
CVE search record: CVE-2026-13610. Severity: high. CVSS: 7.5. EPSS: 0.15%. KEV: no. Product: KiviCare (<= 4.5.1). Brief: Unauthenticated Privilege Escalation in KiviCare WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-08-kivicare-vuln/
KiviCare (a Clinic & Patient Management System plugin for WordPress) contains a critical improper privilege management vulnerability, identified as CVE-2026-13610. The vulnerability exists within the REST API registration endpoint (/wp-json/kivicare/v1/auth/register), which fails to properly authenticate or authorize requests.
An unauthenticated attacker can interact with this endpoint to create new user accounts. By manipulating the user_role parameter, the attacker can force the creation of accounts with elevated permissions, specifically kiviCare_doctor or kiviCare_receptionist, instead of the intended kiviCare_patient role. Furthermore, the application fails to enforce the patient_role_only parameter, and the permission callback defaults to allowing the action without performing nonce or session validation. This allows an attacker to gain a valid administrative foothold in the WordPress instance and access sensitive patient protected health information (PHI) such as appointments, prescriptions, and billing records.
Attack Chain
- Attacker performs reconnaissance to identify a target site running the vulnerable KiviCare WordPress plugin.
- Attacker interacts with the unauthenticated registration endpoint at
POST /wp-json/kivicare/v1/auth/register. - Attacker bypasses the E2EE mechanism by retrieving the
server-keyvia the publicly accessibleConfigController. - Attacker sends a crafted JSON payload containing a chosen username, email, password, and the elevated
user_role(e.g.,kiviCare_doctor). - The plugin fails to perform a permission callback check, authorizing the request due to a default
return truelogic flaw. - The
wp_insert_user()function creates the account, andsetRole()assigns the requested elevated role to the new user. - Attacker authenticates with the newly created account via the REST API.
- Attacker leverages the elevated role to query API endpoints, exfiltrating patient PHI and performing administrative actions.
Impact
Successful exploitation allows unauthenticated attackers to create unauthorized privileged accounts on vulnerable WordPress sites. This results in full access to the medical clinic's management dashboard, including sensitive patient PHI such as medical history, prescriptions, and financial data, leading to severe privacy violations and compliance risks.
Recommendation
Prioritized actions for detection engineering and security teams:
- Deploy the WAF rules below to block unauthorized registration requests to the vulnerable API endpoint.
- Audit the WordPress user database for unauthorized accounts assigned to the
kiviCare_doctororkiviCare_receptionistroles created after August 15, 2026. - Patch the KiviCare plugin to a version above 4.5.1 immediately.
- If a patch is unavailable, disable new user registrations or explicitly restrict access to the
/wp-json/kivicare/v1/endpoint at the web server level.
Immediate actions
Block access to /wp-json/kivicare/v1/auth/register for external traffic
Threat Hunt
Search user database for accounts with roles kiviCare_doctor or kiviCare_receptionist created since 2026-08-15
Data: WordPress database logs
Mitigations
Upgrade KiviCare to version > 4.5.1
CVE-2026-13610
Detection coverage 1
Detect CVE-2026-13610 Exploitation - Unauthorized KiviCare Registration
highDetects unauthorized attempts to register users via the KiviCare API with privileged roles.
Detection queries are available on the platform. Get full rules →