Junglewise Threat Intelligence

CVE-2026-11990: Iqonic Design KiviCare EHR authorization bypass in appointments

CVE-2026-11990 · Severity: medium · CVSS 5.3 · Published 2026-07-10

Technologies: Iqonic Design KiviCare. Vendors: Iqonic Design.

Executive brief

The KiviCare plugin for WordPress, which manages clinic appointments and patient records, contains a security flaw that allows unauthorized users to bypass payment requirements. An attacker can exploit this to mark pending medical appointments as 'Confirmed' without actually paying for them. This could lead to financial loss for clinics and disruption of legitimate scheduling operations.

Technical details

The KiviCare plugin for WordPress is vulnerable to a missing authorization check (CWE-862) in its appointment handling logic. Due to improper verification of user permissions and a flaw in the gateway resolution logic, the 'KCPayLater' manual gateway remains selectable even if disabled by an administrator. An unauthenticated remote attacker can exploit this to mark arbitrary pending appointments as 'Confirmed' and inject forged payment records into the 'wp_kc_payments_appointment_mappings' table using an attacker-supplied payment ID. This effectively allows for the complete bypass of the payment process for clinic services.

Affected products

  • iqonicdesign KiviCare – Clinic & Patient Management System (EHR) up to, and including, 4.4.0

Timeline

  • 2026-07-10: disclosed: Initial publication of the CVE record

References

Related threats