Executive brief
The KiviCare plugin for WordPress, which manages electronic health records and clinic operations, contains a security flaw that could allow authorized users to access sensitive database information. An attacker with a doctor, receptionist, or clinic admin account could exploit this vulnerability to view data they are not permitted to see. This could lead to the exposure of confidential patient or clinic information, potentially impacting patient privacy and regulatory compliance.
Technical details
A generic SQL injection vulnerability exists in the KiviCare plugin due to insufficient escaping and lack of preparation on the 'orderby' parameter within the KCQueryBuilder.php and DoctorSessionController.php components. The flaw is reachable via the network by authenticated users possessing at least 'doctor' level access or roles (like Receptionist or Clinic Admin) that include the 'doctor_session_list' capability. By supplying malicious SQL commands through the affected parameter, an attacker can append queries to existing database calls to exfiltrate sensitive data. The issue affects all versions up to and including 4.5.0; users should update to the latest patched version available.
Affected products
- iqonicdesign KiviCare – Clinic & Patient Management System (EHR) up to, and including, 4.5.0
Timeline
- 2026-07-11: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/kivicare-clinic-management-system/tags/4.5.0/app/baseClasses/KCQueryBuilder.php
- https://plugins.trac.wordpress.org/browser/kivicare-clinic-management-system/tags/4.5.0/app/baseClasses/KCQueryBuilder.php
- https://plugins.trac.wordpress.org/browser/kivicare-clinic-management-system/tags/4.5.0/app/baseClasses/KCQueryBuilder.php
- https://plugins.trac.wordpress.org/browser/kivicare-clinic-management-system/tags/4.5.0/app/controllers/api/DoctorSessionController.php
- https://plugins.trac.wordpress.org/browser/kivicare-clinic-management-system/tags/4.5.0/app/controllers/api/DoctorSessionController.php
- https://plugins.trac.wordpress.org/browser/kivicare-clinic-management-system/tags/4.5.0/app/controllers/api/DoctorSessionController.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3602561%40kivicare-clinic-management-system&new=3602561%40kivicare-clinic-management-system