Executive brief
KiviCare is a clinic management system WordPress plugin used to manage patient records and clinic operations. A flaw in the plugin allows authenticated clinic staff members (doctors or receptionists) to inject malicious SQL commands through a search field, potentially exposing sensitive data such as patient records or administrator credentials. The vulnerability requires staff-level access but could lead to unauthorized access to confidential health and business information.
Technical details
The plugin fails to properly sanitize and escape the searchTerm parameter before using it in a SQL LIKE query on the /wp-json/kivicare/v1/settings/listing REST endpoint. The parameter is passed through sanitize_text_field and esc_like, but these functions do not strip or escape single quotes, allowing an authenticated attacker to break out of the LIKE literal and inject arbitrary SQL. An attacker with clinic staff-level role (kiviCare_doctor or kiviCare_receptionist) and access to a valid REST nonce can execute time-based SQL injection to extract arbitrary database contents, including administrator credentials. The vulnerability has been patched in version 4.5.2 by properly validating and escaping the searchTerm parameter.
Affected products
- Revamp Studio KiviCare before 4.5.2
Timeline
- 2026-08-10: disclosed
- 2026-08-12: patched: Fixed in version 4.5.2