{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/kivicare--4.5.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-13610"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["KiviCare (\u003c= 4.5.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["KiviCare"],"content_html":"\u003cp\u003eKiviCare (a Clinic \u0026amp; Patient Management System plugin for WordPress) contains a critical improper privilege management vulnerability, identified as CVE-2026-13610. The vulnerability exists within the REST API registration endpoint (\u003ccode\u003e/wp-json/kivicare/v1/auth/register\u003c/code\u003e), which fails to properly authenticate or authorize requests.\u003c/p\u003e\n\u003cp\u003eAn unauthenticated attacker can interact with this endpoint to create new user accounts. By manipulating the \u003ccode\u003euser_role\u003c/code\u003e parameter, the attacker can force the creation of accounts with elevated permissions, specifically \u003ccode\u003ekiviCare_doctor\u003c/code\u003e or \u003ccode\u003ekiviCare_receptionist\u003c/code\u003e, instead of the intended \u003ccode\u003ekiviCare_patient\u003c/code\u003e role. Furthermore, the application fails to enforce the \u003ccode\u003epatient_role_only\u003c/code\u003e parameter, and the permission callback defaults to allowing the action without performing nonce or session validation. This allows an attacker to gain a valid administrative foothold in the WordPress instance and access sensitive patient protected health information (PHI) such as appointments, prescriptions, and billing records.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify a target site running the vulnerable KiviCare WordPress plugin.\u003c/li\u003e\n\u003cli\u003eAttacker interacts with the unauthenticated registration endpoint at \u003ccode\u003ePOST /wp-json/kivicare/v1/auth/register\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker bypasses the E2EE mechanism by retrieving the \u003ccode\u003eserver-key\u003c/code\u003e via the publicly accessible \u003ccode\u003eConfigController\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker sends a crafted JSON payload containing a chosen username, email, password, and the elevated \u003ccode\u003euser_role\u003c/code\u003e (e.g., \u003ccode\u003ekiviCare_doctor\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe plugin fails to perform a permission callback check, authorizing the request due to a default \u003ccode\u003ereturn true\u003c/code\u003e logic flaw.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003ewp_insert_user()\u003c/code\u003e function creates the account, and \u003ccode\u003esetRole()\u003c/code\u003e assigns the requested elevated role to the new user.\u003c/li\u003e\n\u003cli\u003eAttacker authenticates with the newly created account via the REST API.\u003c/li\u003e\n\u003cli\u003eAttacker leverages the elevated role to query API endpoints, exfiltrating patient PHI and performing administrative actions.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to create unauthorized privileged accounts on vulnerable WordPress sites. This results in full access to the medical clinic's management dashboard, including sensitive patient PHI such as medical history, prescriptions, and financial data, leading to severe privacy violations and compliance risks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection engineering and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the WAF rules below to block unauthorized registration requests to the vulnerable API endpoint.\u003c/li\u003e\n\u003cli\u003eAudit the WordPress user database for unauthorized accounts assigned to the \u003ccode\u003ekiviCare_doctor\u003c/code\u003e or \u003ccode\u003ekiviCare_receptionist\u003c/code\u003e roles created after August 15, 2026.\u003c/li\u003e\n\u003cli\u003ePatch the KiviCare plugin to a version above 4.5.1 immediately.\u003c/li\u003e\n\u003cli\u003eIf a patch is unavailable, disable new user registrations or explicitly restrict access to the \u003ccode\u003e/wp-json/kivicare/v1/\u003c/code\u003e endpoint at the web server level.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-15T05:25:51Z","date_published":"2026-08-15T05:25:51Z","id":"https://feed.craftedsignal.io/briefs/2026-08-kivicare-vuln/","summary":"The KiviCare WordPress plugin (\u003c= 4.5.1) is vulnerable to unauthenticated account creation via its REST API, allowing attackers to escalate privileges to doctor or receptionist roles and access sensitive patient PHI.","title":"Unauthenticated Privilege Escalation in KiviCare WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-kivicare-vuln/"}],"language":"en","title":"CraftedSignal Threat Feed - KiviCare (\u003c= 4.5.1)","version":"https://jsonfeed.org/version/1.1"}